# problems with &\*\_expire attributes

**URL:** <https://community.zeek.org/t/problems-with-expire-attributes/665>\
**Category:** Zeek\
**Created:** [December 28, 2004, 6:45am UTC](https://community.zeek.org/t/problems-with-expire-attributes/665 "2004-12-28T06:45:36Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vern](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/vern/32/630_2.png) [@Vern](https://community.zeek.org/u/Vern)\
**Post date:** [December 28, 2004, 6:45am UTC](https://community.zeek.org/t/problems-with-expire-attributes/665/1 "2004-12-28T06:45:36Z")

</div>

> i'm fighting with some problems:  
> i encountered problems with the &\*\_expire attributes of table entries.  
> it seems that they have no influence, nothing happens at all.
> 
> i wrote the policy script below (don't ask for the purpose of this  
> script, i just wrote it to learn bro) and i thought it should alarm more  
> than once, if a host contacts unreachable hosts after a while. well, it  
> does it only once and the function test is never called:  
> \> 1103883009.796358 TRWAddressScan x.x.x.x scanned a total of 4 hosts  
> \> 1103883009.796358 x.x.x.x connected 10 unreachable hosts  
> \> 1103883010.358487 AddressScan x.x.x.x has scanned 100 hosts (ftp-data)  
> \> 1103883010.358487 x.x.x.x connected 100 unreachable hosts  
> \> 1103883013.343568 x.x.x.x connected 1000 unreachable hosts  
> \> 1103883013.343568 AddressScan x.x.x.x has scanned 1000 hosts (ftp-data)  
> \> 1103883036.284724 TRWScanSummary x.x.x.x scanned a total of 4 hosts

What do you mean it should "alarm more than once"? It is indeed generating  
multiple alarms (10 unreachable, 100 unreachable, 1000 unreachable).

Also, you need to clarify why would you expect "test" to be called.  
All of the expirations you set:

> \> global failed\_connection\_counter: table[addr] of count &read\_expire=30sec  
> \> &write\_expire=30sec &create\_expire=30sec &expire\_func=test;

are for 30 seconds after the last of different types of activity, yet the  
timestamps of the alarm output you show span just a few seconds, so this  
doesn't appear to be enough time for any of the expirations to occur.

&nbsp;&nbsp;&nbsp;&nbsp;Vern

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:37pm UTC](https://community.zeek.org/t/problems-with-expire-attributes/665/2 "2022-05-06T15:37:18Z")

</div>


