# New Bro User

**URL:** https://community.zeek.org/t/new-bro-user/1333
**Category:** Zeek
**Created:** [May 12, 2008, 1:47pm UTC](https://community.zeek.org/t/new-bro-user/1333 "2008-05-12T13:47:19Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![Jesse\_Bortercollet](https://avatars.discourse-cdn.com/v4/letter/j/9e8a1a/32.png) [@Jesse\_Bortercollet](https://community.zeek.org/u/Jesse_Bortercollet)
#### Post date: [May 12, 2008, 1:47pm UTC](https://community.zeek.org/t/new-bro-user/1333/1 "2008-05-12T13:47:19Z")

</div>

Hi,

I’m trying to become familiar with Bro and have installed the stable release 1.2.1 on an Ubuntu VMware image running a 2.6 kernel.

I have been following the documentation and wanted to see if I have everything installed properly by first reading a pcap to generate an alarm. I was looking at the reference manual, specifically Chapter 2: Getting Started [2.1.4.2](http://2.1.4.2) Traffic traces. I wanted to emulate the:

bro -r example.ftp-attack.trace brolite

where I was supposed to see a connection summary in stdout and some kind of alarm. I didn’t find that particular pcap with the installation as the documentation says, but used a pcap from an earlier bro package - ftp-site-exec.trace. I ran the bro above command using this pcap, but I don’t see any output at all. I’m familiar with Snort so I’ve used an IDS before. I just can’t figure out what I might be doing wrong. Can someone please help?

Thanks a lot - Jesse

---

<div class="post-metadata">

### Author: ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)
#### Post date: [May 6, 2022, 3:38pm UTC](https://community.zeek.org/t/new-bro-user/1333/2 "2022-05-06T15:38:33Z")

</div>


