# New Analyzer

**URL:** <https://community.zeek.org/t/new-analyzer/5758>\
**Category:** Zeek\
**Created:** [July 10, 2019, 1:44am UTC](https://community.zeek.org/t/new-analyzer/5758 "2019-07-10T01:44:35Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aaron\_Heller](https://avatars.discourse-cdn.com/v4/letter/a/d6d6ee/32.png) [@Aaron\_Heller](https://community.zeek.org/u/Aaron_Heller)\
**Post date:** [July 10, 2019, 1:44am UTC](https://community.zeek.org/t/new-analyzer/5758/1 "2019-07-10T01:44:35Z")

</div>

Hi everyone,

I’m working on a BACnet protocol analyzer for Zeek and am having problems getting the analyzer to fire. I’ve been working with Zeek version 2.6.2 and the analyzer was created using binpac\_quickstart.

BACnet is a UDP based building automation and control protocol (think furnaces, security/access systems, lighting, etc.).

Not sure what info would be most helpful, if anyone is willing to lend some insight as why the analyzer isn’t firing off? The analyzer is supposed to be signature based and bro -N shows it as built-in and active. If bro -s option is used to specify the signature file then the analyzer will fire off appropriately, but I’m looking for it to auto-magically be included in the UDP analyzer tree.

Greatly appreciate any help or thought for where to look first,  
Aaron

---

<div class="post-metadata">

**Author:** ![Palumbo\_Mauro](https://avatars.discourse-cdn.com/v4/letter/p/7c8e57/32.png) [@Palumbo\_Mauro](https://community.zeek.org/u/Palumbo_Mauro)\
**Post date:** [July 10, 2019, 7:30am UTC](https://community.zeek.org/t/new-analyzer/5758/2 "2019-07-10T07:30:18Z")

</div>

Hi Aaron,

not sure what you have done so far, but maybe you are missing something on the script side?

To activate signature recognition for analyzers, you must write a script with the proper signature (usually called dpd.sig) and load it (usually with @load-sigs ./dpd.sig in the main.zeek script for the analyzer).

Have a look at the script side of some other analyzers to see some examples.

Mauro

**Inviato:** mercoledì 10 luglio 2019 03:45

![image001.jpg](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/9012a412e731bff98ab598c3cff7750721ecae34.jpeg)

---

<div class="post-metadata">

**Author:** ![Aaron\_Heller](https://avatars.discourse-cdn.com/v4/letter/a/d6d6ee/32.png) [@Aaron\_Heller](https://community.zeek.org/u/Aaron_Heller)\
**Post date:** [July 11, 2019, 12:07am UTC](https://community.zeek.org/t/new-analyzer/5758/3 "2019-07-11T00:07:45Z")

</div>

Hi Mauro,  
Thanks much for the idea/insight.

I didn’t have a @load-sigs line in the main.bro script, but there is one in the **load**.bro file. It looks consistent with the other protocols that appear to be signature based (dnp3, ftp, pop3, etc.). I tried adding the @load-sigs ./dpd.sig line to the main.bro script but still no joy. Any other thoughts?

I didn’t think to include it in the original email, but when zeek is run with the -s option and a signature file is specified, the ‘C’ portion of the analyzer fires off (i.e., the …/zeek/src/analyzers/protocol/bacnet/bacnet.cc, Plugin.cc, and events.bif), but the script side that should generate a log file does not (…/zeek/scripts/base/protocols/bacnet/main.bro, **load**.bro, and dpd.sig). Maybe that and the analyzer not automatically firing off indicates an issue with the bacnet script not being called appropriately? I’m grasping at straws, so any thoughts are greatly appreciated!

Thanks again,  
Aaron

![image001.jpg](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/9012a412e731bff98ab598c3cff7750721ecae34.jpeg)

---

<div class="post-metadata">

**Author:** ![JustinAzoff](https://avatars.discourse-cdn.com/v4/letter/j/13edae/32.png) [@JustinAzoff](https://community.zeek.org/u/JustinAzoff)\
**Post date:** [July 11, 2019, 12:20am UTC](https://community.zeek.org/t/new-analyzer/5758/4 "2019-07-11T00:20:20Z")

</div>

I don’t think you are loading the scripts at all… which is also why the sigs aren’t loaded.

Are you building this as an in-tree analyzer or as an external plugin?

![image001.jpg](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/9012a412e731bff98ab598c3cff7750721ecae34.jpeg)

---

<div class="post-metadata">

**Author:** ![Aaron\_Heller](https://avatars.discourse-cdn.com/v4/letter/a/d6d6ee/32.png) [@Aaron\_Heller](https://community.zeek.org/u/Aaron_Heller)\
**Post date:** [July 11, 2019, 12:39am UTC](https://community.zeek.org/t/new-analyzer/5758/5 "2019-07-11T00:39:07Z")

</div>

Hi Justin,  
I started off using the binpac\_quickstart script, which I thought created an external plugin?

Thanks,  
Aaron

---

<div class="post-metadata">

**Author:** ![JustinAzoff](https://avatars.discourse-cdn.com/v4/letter/j/13edae/32.png) [@JustinAzoff](https://community.zeek.org/u/JustinAzoff)\
**Post date:** [July 11, 2019, 12:51am UTC](https://community.zeek.org/t/new-analyzer/5758/6 "2019-07-11T00:51:41Z")

</div>

did you run that with --plugin?

---

<div class="post-metadata">

**Author:** ![JustinAzoff](https://avatars.discourse-cdn.com/v4/letter/j/13edae/32.png) [@JustinAzoff](https://community.zeek.org/u/JustinAzoff)\
**Post date:** [July 11, 2019, 1:01am UTC](https://community.zeek.org/t/new-analyzer/5758/7 "2019-07-11T01:01:10Z")

</div>

Oh, looking at this closer you probably want to use

zeek/aux/zeek-aux/plugin-support/init-plugin

to create the plugin skeleton. the binpac quickstart I think is a bit  
out of date at this point for how to setup an external plugin+package.  
The binpac parts it genrates should still be fine though.

so I would use init-plugin to make a new package and copy your  
existing code over it. that should give you a working self-contained  
external package that you can install. It also takes advantage of the  
new bro-config bits which make building and installing the plugin work  
without the full source checkout.

---

<div class="post-metadata">

**Author:** ![Aaron\_Heller](https://avatars.discourse-cdn.com/v4/letter/a/d6d6ee/32.png) [@Aaron\_Heller](https://community.zeek.org/u/Aaron_Heller)\
**Post date:** [July 11, 2019, 1:11am UTC](https://community.zeek.org/t/new-analyzer/5758/8 "2019-07-11T01:11:46Z")

</div>

I did try running with the bacnet plugin specified and it didn’t work, so I’ll give the init-plugin a shot tomorrow.

Thanks much all for the thoughts and help,  
Aaron

---

<div class="post-metadata">

**Author:** ![Palumbo\_Mauro](https://avatars.discourse-cdn.com/v4/letter/p/7c8e57/32.png) [@Palumbo\_Mauro](https://community.zeek.org/u/Palumbo_Mauro)\
**Post date:** [July 11, 2019, 8:15am UTC](https://community.zeek.org/t/new-analyzer/5758/9 "2019-07-11T08:15:25Z")

</div>

Hi Aaron,

I can confirm the binpac quickstart is a bit out of date. I tried to use it a couple of months ago and run into some issues. You can still use it but then have to edit some files manually.

Mauro

**Inviato:** giovedì 11 luglio 2019 03:12

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:46pm UTC](https://community.zeek.org/t/new-analyzer/5758/10 "2022-05-06T15:46:37Z")

</div>


