# Links in SMTP round 2

**URL:** <https://community.zeek.org/t/links-in-smtp-round-2/2899>\
**Category:** Zeek\
**Created:** [November 8, 2013, 2:25pm UTC](https://community.zeek.org/t/links-in-smtp-round-2/2899 "2013-11-08T14:25:07Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [November 8, 2013, 2:25pm UTC](https://community.zeek.org/t/links-in-smtp-round-2/2899/1 "2013-11-08T14:25:07Z")

</div>

So here’s where I’m at:

event bro\_init()  
&nbsp;&nbsp;&nbsp;&nbsp;{  
&nbsp;&nbsp;&nbsp;&nbsp;local filter: Log::Filter = [$name="smtp-http", $path="smtp-http", $include=set("ts", "uid", "id.orig\_h", "id.orig\_p", "id.resp\_h", "id.resp\_p", "mailfrom", "rcptto", "date", "from", "to", "reply\_to"  
, "msg\_id", "subject")];  
&nbsp;&nbsp;&nbsp;&nbsp;Log::add\_filter(SMTP::LOG, filter);  
&nbsp;&nbsp;&nbsp;&nbsp;}

redef record SMTP::Info += {  
&nbsp;&nbsp;&nbsp;&nbsp;smtp\_http: string &log;  
};

event mime\_entity\_data(c:connection, length: count, data:string)

My snags are:

error in /usr/local/bro/share/bro/base/protocols/smtp/./main.bro, line 10: extension field must be &optional or have &default (SMTP::Info)  
error in ./testfiles/test.bro, line 12: syntax error, at end of file

I’m hoping the first error is because I haven’t defined the new field of smtp\_http yet. As for the second, I’m not sure how to create that field. I’ve been looking heavily at [http://www.bro.org/sphinx-git/frameworks/logging.html](http://www.bro.org/sphinx-git/frameworks/logging.html), but so far this is all I have. ANY help…tutorials…pointers…something would really save me some time. Thank you.

James

---

<div class="post-metadata">

**Author:** ![Azoff\_Justin](https://avatars.discourse-cdn.com/v4/letter/a/5fc32e/32.png) [@Azoff\_Justin](https://community.zeek.org/u/Azoff_Justin)\
**Post date:** [November 8, 2013, 3:07pm UTC](https://community.zeek.org/t/links-in-smtp-round-2/2899/2 "2013-11-08T15:07:30Z")

</div>

> error in /usr/local/bro/share/bro/base/protocols/smtp/./main.bro, line 10: extension field must be &optional or have &default (SMTP::Info)

Yep.. you need to mark it as &optional like it says.

> error in ./testfiles/test.bro, line 12: syntax error, at end of file

You just need to handle that event and extract the links.

> I’m hoping the first error is because I haven’t defined the new field of smtp\_http yet. As for the second, I’m not sure how to create that field. I’ve been looking heavily at [http://www.bro.org/sphinx-git/frameworks/logging.html](http://www.bro.org/sphinx-git/frameworks/logging.html), but so far this is all I have. ANY help…tutorials…pointers…something would really save me some time. Thank you.

Here is a script that adds a field to the conn log, it does all the  
things you need to do:

> <https://github.com/JustinAzoff/bro_scripts/blob/master/conn-hostnames.bro>

---

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [November 8, 2013, 3:57pm UTC](https://community.zeek.org/t/links-in-smtp-round-2/2899/3 "2013-11-08T15:57:38Z")

</div>

Thanks a BUNCH Justin…this helps. As I’m looking at this, I think what I’m hoping for, is something like:

"if the smtp message stream contains http, then log the link to smtp\_http.log, otherwise don’t log anything about the stream to smtp\_http.log"

Something I’m stumbling on is…how do I specify the smtp stream, and how do I find out if it contains http ( looking at the bro cheat sheet I don’t see “=~” ). Again, thanks so much Justin…I think I’m getting closer.

James

---

<div class="post-metadata">

**Author:** ![Azoff\_Justin](https://avatars.discourse-cdn.com/v4/letter/a/5fc32e/32.png) [@Azoff\_Justin](https://community.zeek.org/u/Azoff_Justin)\
**Post date:** [November 8, 2013, 4:31pm UTC](https://community.zeek.org/t/links-in-smtp-round-2/2899/4 "2013-11-08T16:31:30Z")

</div>

You pasted how to do this in your first message:

event mime\_entity\_data(c:connection, length: count, data:string)  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;{ print find\_all\_urls(data); }

The only tricky part is find\_all\_urls would return a vector so your log  
field needs to be a 'vector of string' and not just a 'string'

---

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [November 8, 2013, 4:34pm UTC](https://community.zeek.org/t/links-in-smtp-round-2/2899/5 "2013-11-08T16:34:51Z")

</div>

Awesome…thank you much Justin.

James

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:41pm UTC](https://community.zeek.org/t/links-in-smtp-round-2/2899/6 "2022-05-06T15:41:23Z")

</div>


