# piping to a text file

**URL:** <https://community.zeek.org/t/piping-to-a-text-file/486>\
**Category:** Zeek\
**Created:** [April 1, 2004, 12:04pm UTC](https://community.zeek.org/t/piping-to-a-text-file/486 "2004-04-01T12:04:06Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bryan](https://avatars.discourse-cdn.com/v4/letter/b/db5fbb/32.png) [@Bryan](https://community.zeek.org/u/Bryan)\
**Post date:** [April 1, 2004, 12:04pm UTC](https://community.zeek.org/t/piping-to-a-text-file/486/1 "2004-04-01T12:04:06Z")

</div>

Hello again,

I know that you can pipe results to a binary file with the -w flag and  
then you can read it with the -r flag using bro again. While running  
bro, can you pipe the output to a text file?  
i.e. \>bro -r \<filename\> mt \>\> readResults //where 'readResults' is my  
new file

I can't get it to work.

Thanks,  
Bryan  
Florida Tech

---

<div class="post-metadata">

**Author:** ![Bryan](https://avatars.discourse-cdn.com/v4/letter/b/db5fbb/32.png) [@Bryan](https://community.zeek.org/u/Bryan)\
**Post date:** [April 1, 2004, 3:26pm UTC](https://community.zeek.org/t/piping-to-a-text-file/486/2 "2004-04-01T15:26:34Z")

</div>

Hello,

I am reading tcpdump trace files that my professor gave me.

[root@localhost bro\_files]# bro -r tcpdump/attack\_file\_8.tcpdump mt -w  
scan\_results/attack8.scan

I am writing them to 'attack8.scan', but that is a binary file which I  
need to read with bro again. On that note, what is the proper  
syntax/flag to use when reading bro output "as-is" with the bro  
application?

#bro -r attack8.scan \<???\>

THANKS!  
Bryan

---

<div class="post-metadata">

**Author:** ![Bryan](https://avatars.discourse-cdn.com/v4/letter/b/db5fbb/32.png) [@Bryan](https://community.zeek.org/u/Bryan)\
**Post date:** [April 1, 2004, 4:13pm UTC](https://community.zeek.org/t/piping-to-a-text-file/486/3 "2004-04-01T16:13:08Z")

</div>

Hello,

> The binary file is in tcpdump format, so you can use tcpdump -r \<file\> to  
> see the trace in text format (try flag -nX).

Where does the '-nX' flag go? tcpdump or bro? Does it go in place of the  
'-r' or appended to it?

> Also if you say 'bro ... -w  
> -', the output trace will be dumped to stdout and you can pipe it with  
> tcpdump as well.

> From the following line...

&nbsp;&nbsp;\>#bro -r \<trace file\> mt -w \<output file\>  
How do I do what you are saying above so that I can read the data in a  
text reader (vi,gedit,emacs...)?

I am running a bash shell on Fedora/Redhat.  
Sorry, I have only been "officially" running Linux for a few months.

> Does this answer your question? (I don't know what you meant by "as-is"  
> though.)

When I said "as-is" I just meant that I didn't want bro to analyze the  
data, just repeat it back.

THANKS!  
Bryan

---

<div class="post-metadata">

**Author:** ![Bryan](https://avatars.discourse-cdn.com/v4/letter/b/db5fbb/32.png) [@Bryan](https://community.zeek.org/u/Bryan)\
**Post date:** [April 1, 2004, 4:50pm UTC](https://community.zeek.org/t/piping-to-a-text-file/486/4 "2004-04-01T16:50:43Z")

</div>

Thanks for the help!

Bryan

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:36pm UTC](https://community.zeek.org/t/piping-to-a-text-file/486/5 "2022-05-06T15:36:59Z")

</div>


