# measuring zeek's performance

**URL:** <https://community.zeek.org/t/measuring-zeeks-performance/5639>\
**Category:** Development\
**Tags:** development\
**Created:** [March 19, 2019, 9:48am UTC](https://community.zeek.org/t/measuring-zeeks-performance/5639 "2019-03-19T09:48:57Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mauro\_Palumbo](https://avatars.discourse-cdn.com/v4/letter/m/c2a13f/32.png) [@Mauro\_Palumbo](https://community.zeek.org/u/Mauro_Palumbo)\
**Post date:** [March 19, 2019, 9:48am UTC](https://community.zeek.org/t/measuring-zeeks-performance/5639/1 "2019-03-19T09:48:57Z")

</div>

Dear Zeek-devs,  
I think it is a common experience to need to evaluate zeek’s performance according to different customizations at the script level, when using an event rather than another or a new plugin. Obviously this heavily depends on the traffic zeek is analyzing. But it would be of great help if there were a tool which could count the amount of time zeek has spent on certain events/plugins when analyzing traffic. Is something like this available?

Thanks in advance.  
Mauro

---

<div class="post-metadata">

**Author:** ![Jim\_Mellander](https://avatars.discourse-cdn.com/v4/letter/j/e47c2d/32.png) [@Jim\_Mellander](https://community.zeek.org/u/Jim_Mellander)\
**Post date:** [March 20, 2019, 7:24pm UTC](https://community.zeek.org/t/measuring-zeeks-performance/5639/2 "2019-03-20T19:24:56Z")

</div>

The attached may prove useful. The contents are:

1. instrument.sh - awk script that takes a bro script in stdin & outputs the script with instrumentation added. It does a passable job of adding instrumentation to entry & exits of functions/events/hooks, although at times there is manual fixup required. To do an exact job would require a full bro language parser, which was more than I wanted to tackle (although in a fit of experimentation, I did once write a recursive descent compiler-compiler in awk)
2. Instrument.bro - which prints timestamps upon function entry & exit (for production use, this probably needs to be a logfile). This needs to be @load’ed before the bro scripts that you’ve instrumented. By processing the log & matching up the function calls, the elapsed time in the function can be calculated. This could also be expanded to record memory usage before & after, if that is of interest.  
I never got around to productionizing this, but hopefully it will be of interest…

Hope this helps,

Jim

[instrument.tar](https://community.zeek.org/uploads/short-url/dy8z37iCSBFRb5qJfMqWj5Uqlze.tar) (6 KB)

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:46pm UTC](https://community.zeek.org/t/measuring-zeeks-performance/5639/3 "2022-05-06T15:46:23Z")

</div>


