# Log entire payloads

**URL:** <https://community.zeek.org/t/log-entire-payloads/498>\
**Category:** Zeek\
**Created:** [April 23, 2004, 1:54pm UTC](https://community.zeek.org/t/log-entire-payloads/498 "2004-04-23T13:54:49Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yohann\_THOMAS](https://avatars.discourse-cdn.com/v4/letter/y/f9ae1b/32.png) [@Yohann\_THOMAS](https://community.zeek.org/u/Yohann_THOMAS)\
**Post date:** [April 23, 2004, 1:54pm UTC](https://community.zeek.org/t/log-entire-payloads/498/1 "2004-04-23T13:54:49Z")

</div>

Hi everybody !!!

I'd like to log http payloads for each connection seen on my network.

In fact, I'd like to get something like :  
Src\_IP;Dst\_IP;Request\_Payload;Reply\_Payload

but with entire payloads (not only URIs, but also banners...)

At the moment, the only way I found to manage that is to load the signature module and write a signature file using payload /.\*/, in order to get the payloads on signature\_match events with the data string.

It works, but unfortunately, this solution is a bit heavy in term of CPU usage. There's probably a way to get these payloads using a built-in function (and avoiding signatures module) ??? In fact, having a look at the http-related modules, I can't find how I can handle this problem...

Anybody to help me ??? (or just to tell me it's not possible with built-in functionnalities... ;-( )

Yohann.

---

<div class="post-metadata">

**Author:** ![Ruoming\_Pang](https://avatars.discourse-cdn.com/v4/letter/r/df788c/32.png) [@Ruoming\_Pang](https://community.zeek.org/u/Ruoming_Pang)\
**Post date:** [April 23, 2004, 2:41pm UTC](https://community.zeek.org/t/log-entire-payloads/498/2 "2004-04-23T14:41:16Z")

</div>

> I'd like to log http payloads for each connection seen on my network.
> 
> In fact, I'd like to get something like :  
> Src\_IP;Dst\_IP;Request\_Payload;Reply\_Payload
> 
> but with entire payloads (not only URIs, but also banners...)

Hi, Yohann,

One possibility is to load the contents.bro script. It will write the  
contents of every connection to two files (contents-\*), one for each  
direction. Note that it does writing for every connection, not just HTTP  
ones. If you want the latter, you might want to adapt the script  
accordingly.

Ruoming

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:37pm UTC](https://community.zeek.org/t/log-entire-payloads/498/3 "2022-05-06T15:37:00Z")

</div>


