# problem with &expire\_func

**URL:** <https://community.zeek.org/t/problem-with-expire-func/690>\
**Category:** Zeek\
**Created:** [February 10, 2005, 10:55am UTC](https://community.zeek.org/t/problem-with-expire-func/690 "2005-02-10T10:55:01Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Christoph\_Goeldi](https://avatars.discourse-cdn.com/v4/letter/c/e5b9ba/32.png) [@Christoph\_Goeldi](https://community.zeek.org/u/Christoph_Goeldi)\
**Post date:** [February 10, 2005, 10:55am UTC](https://community.zeek.org/t/problem-with-expire-func/690/1 "2005-02-10T10:55:01Z")

</div>

hi there

i found another problem with bro.  
this time it is the expire\_func which makes trouble.  
when i have a policy file like this:

> global mytable: table[addr] of bool &write\_expire=10sec &expire\_func=myfunc;
> 
> function myfunc(t: table[addr] of bool , idx: any): interval {  
> &nbsp;&nbsp;&nbsp;&nbsp;local srcIP: addr;  
> &nbsp;&nbsp;&nbsp;&nbsp;

\> print network\_time(),"help!!!";

> &nbsp;&nbsp;&nbsp;&nbsp;[srcIP] = idx;
> 
> &nbsp;&nbsp;&nbsp;&nbsp;return 0secs;  
> }

it ends in an error like this:

> 1108032092.49407, help!!!  
> 1108032092.494068 \<no location\> (192.168.0.75): bad tag in Val::CONVERTER

i tested several constellations and noticed, that it is impossible to use idx when a table has only one index.

any help welcome.  
thanx  
christoph

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:37pm UTC](https://community.zeek.org/t/problem-with-expire-func/690/2 "2022-05-06T15:37:21Z")

</div>


