# One-way TCP session to handle HTTP requests only

**URL:** <https://community.zeek.org/t/one-way-tcp-session-to-handle-http-requests-only/3530>\
**Category:** Zeek\
**Created:** [March 25, 2015, 12:11pm UTC](https://community.zeek.org/t/one-way-tcp-session-to-handle-http-requests-only/3530 "2015-03-25T12:11:04Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rovnov\_Pavel](https://avatars.discourse-cdn.com/v4/letter/r/858c86/32.png) [@Rovnov\_Pavel](https://community.zeek.org/u/Rovnov_Pavel)\
**Post date:** [March 25, 2015, 12:11pm UTC](https://community.zeek.org/t/one-way-tcp-session-to-handle-http-requests-only/3530/1 "2015-03-25T12:11:04Z")

</div>

Hello!

I’m looking for a monitoring solution that will give me an instrument to log all HTTP requests (including HTTPS). I see that Bro does this really well by default. But as soon as I will have huge amount of web traffic (like 10Gb/s+) I would like to process HTTP requests only by mirroring only one-way of TCP sessions. That will save a lot of processing power since HTTP request \<\< HTTP response.

I found only one reference to my idea that say that handling one-way TCP at best will slow down Bro ([http://mailman.icsi.berkeley.edu/pipermail/bro/2006-October/001853.html](http://mailman.icsi.berkeley.edu/pipermail/bro/2006-October/001853.html)). So the questions are:

1. Can anyone confirm that using Bro to handle one-way TCP session is a bad idea?

2. Does anyone have any experience of tuning Bro to handle one-way TCP sessions? We might turn off unnecessary processing (e. g. policies that need 2-way session) to solve the task…

Thanks!

Pavel

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:42pm UTC](https://community.zeek.org/t/one-way-tcp-session-to-handle-http-requests-only/3530/2 "2022-05-06T15:42:32Z")

</div>


