# No info record

**URL:** <https://community.zeek.org/t/no-info-record/3745>\
**Category:** Zeek\
**Created:** [July 31, 2015, 1:59pm UTC](https://community.zeek.org/t/no-info-record/3745 "2015-07-31T13:59:36Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Michael\_Black](https://avatars.discourse-cdn.com/v4/letter/m/b782af/32.png) [@Michael\_Black](https://community.zeek.org/u/Michael_Black)\
**Post date:** [July 31, 2015, 1:59pm UTC](https://community.zeek.org/t/no-info-record/3745/1 "2015-07-31T13:59:36Z")

</div>

Using 2.4

I’m having a problem in a connection\_finished event. I’ve extended the connection record with an extra field.

But….processing a 512MB capture file I have I get a number of connection events that don’t have a c$conn record in them.

I get the same behavior using connection\_EOF.

This script demonstrates the problem. I’ve attached a sample of the conn.log records that show a mix of good/bad where you can see the TEST1 and N/A default on the non-conn records.

1426100429.761609 expression error in ./test.bro, line 11: field value missing [c$conn]

It seems that if there is no “string” value or if it’s an ssl, dns, for example, then there is no $conn field.

Is there an extendable record in a connection record that is ALWAYS there?

@load base/utils/site

@load base/protocols/conn

redef record Conn::Info += {

testfield: string &default=“N/A” &log;

};

event connection\_finished(c: connection)

{

if (!c?$conn) {

c$conn$testfield = “TEST2”;

}

else {

print(“TEST1”);

c$conn$testfield = “TEST1”;

}

}

[badconn.txt](https://community.zeek.org/uploads/short-url/a76JTlQlQhB9tGTDXYgwLDMk3UF.txt) (3.13 KB)

---

<div class="post-metadata">

**Author:** ![Michael\_Black](https://avatars.discourse-cdn.com/v4/letter/m/b782af/32.png) [@Michael\_Black](https://community.zeek.org/u/Michael_Black)\
**Post date:** [August 5, 2015, 5:08pm UTC](https://community.zeek.org/t/no-info-record/3745/2 "2015-08-05T17:08:16Z")

</div>

Fixed the problem by using connection\_state\_remove event instead.

It appears many protocols don’t add the conn fields until after the connection\_finished event.

Mike

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:42pm UTC](https://community.zeek.org/t/no-info-record/3745/3 "2022-05-06T15:42:55Z")

</div>


