# Log entire payloads

**URL:** <https://community.zeek.org/t/log-entire-payloads/500>\
**Category:** Zeek\
**Created:** [April 24, 2004, 7:02pm UTC](https://community.zeek.org/t/log-entire-payloads/500 "2004-04-24T19:02:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vern](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/vern/32/630_2.png) [@Vern](https://community.zeek.org/u/Vern)\
**Post date:** [April 24, 2004, 7:02pm UTC](https://community.zeek.org/t/log-entire-payloads/500/1 "2004-04-24T19:02:40Z")

</div>

> One possibility is to load the contents.bro script. It will write the  
> contents of every connection to two files (contents-\*), one for each  
> direction. Note that it does writing for every connection, not just HTTP  
> ones. If you want the latter, you might want to adapt the script  
> accordingly.

Note, depending on your broader use, you can avoid adapting the script  
by using capture\_filters to only capture tcp port 80.

&nbsp;&nbsp;&nbsp;&nbsp;Vern

---

<div class="post-metadata">

**Author:** ![Shekhar\_Reddy\_Gaddam](https://avatars.discourse-cdn.com/v4/letter/s/c77e96/32.png) [@Shekhar\_Reddy\_Gaddam](https://community.zeek.org/u/Shekhar_Reddy_Gaddam)\
**Post date:** [April 26, 2004, 3:34pm UTC](https://community.zeek.org/t/log-entire-payloads/500/2 "2004-04-26T15:34:46Z")

</div>

Dear Dr. Vern,

I'd like to extract 41 features and their corresponding attack classes based on  
the DARPA 1999 dataset and 2000 dataset  
([http://www.ll.mit.edu/IST/ideval/data/data\_index.html](http://www.ll.mit.edu/IST/ideval/data/data_index.html)) like the KDD Cup 99  
dataset ( [http://kdd.ics.uci.edu/databases/kddcup99/kddcup.names](http://kdd.ics.uci.edu/databases/kddcup99/kddcup.names) ). Is it  
possible to extract all the 41 features from tcpdump files. I was able to  
extract 12 features only. I'm newbie to the bro tool, and i'd like to know if i  
can extract all the 41 features from tcpdump files.

Regards,

Shekhar

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:37pm UTC](https://community.zeek.org/t/log-entire-payloads/500/3 "2022-05-06T15:37:00Z")

</div>


