# (no subject)

**URL:** <https://community.zeek.org/t/no-subject/1238>\
**Category:** Zeek\
**Created:** [October 5, 2007, 4:53pm UTC](https://community.zeek.org/t/no-subject/1238 "2007-10-05T16:53:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tenhunen\_Thomas\_CIV](https://avatars.discourse-cdn.com/v4/letter/t/6bbea6/32.png) [@Tenhunen\_Thomas\_CIV](https://community.zeek.org/u/Tenhunen_Thomas_CIV)\
**Post date:** [October 5, 2007, 4:53pm UTC](https://community.zeek.org/t/no-subject/1238/1 "2007-10-05T16:53:00Z")

</div>

Hello Bro developers and users,

I’m new to Bro but I’m thinking about using it in my thesis research. So far the installation of 1.3.2 and 1.2.1 has gone well.

As a test I ran bro against trace1.tcpdump and buffer-overflow-attack.tcpdump which worked fine. Next I created a tcpdump file using tcpdump -w test.out. Tcpdump captured several packets. When bro is ran against this file it kicks out an error:

command given: bro -r test.out tcp

error returned:

line 1: warning: event handlers never invoked:  
line 1: warning: account\_tried

Is there a trick to creating the tcpdump files?

Running FreeBSD 6.2 with libpcap 0.97  
Used root for all commands.  
$PATH is updated with /usr/local/bro/bin

setenv BROPATH /usr/local/bro/policy:/usr/local/bro/site  
setenv BRO\_DNS\_FAKE 1

Any explanation you can share about this error would be great.  
Thanks.

v/r  
Thomas Tenhunen  
Naval Postgraduate School  
Code 368-SFS  
ttenhune@nps.edu

---

<div class="post-metadata">

**Author:** ![Nicholas\_Weaver](https://avatars.discourse-cdn.com/v4/letter/n/c5a1d2/32.png) [@Nicholas\_Weaver](https://community.zeek.org/u/Nicholas_Weaver)\
**Post date:** [October 5, 2007, 5:22pm UTC](https://community.zeek.org/t/no-subject/1238/2 "2007-10-05T17:22:07Z")

</div>

On Fri, Oct 05, 2007 at 09:53:00AM -0700, Tenhunen, Thomas (CIV) composed:

> Hello Bro developers and users,
> 
> I'm new to Bro but I'm thinking about using it in my thesis research. So far the installation of 1.3.2 and 1.2.1 has gone well.
> 
> As a test I ran bro against trace1.tcpdump and buffer-overflow-attack.tcpdump which worked fine. Next I created a tcpdump file using tcpdump -w test.out. Tcpdump captured several packets. When bro is ran against this file it kicks out an error:

Do tcpdump -w test.out -s 0  
so it captures whole packets

By default, tcpdump only grabs headers.

---

<div class="post-metadata">

**Author:** ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)\
**Post date:** [October 5, 2007, 6:10pm UTC](https://community.zeek.org/t/no-subject/1238/3 "2007-10-05T18:10:03Z")

</div>

This is actually not an error but just a warning which you can  
typically ignore. See if Bro created any output in conn.log.

Robin

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:38pm UTC](https://community.zeek.org/t/no-subject/1238/4 "2022-05-06T15:38:22Z")

</div>


