# Receiving bro events via broccoli API

**URL:** <https://community.zeek.org/t/receiving-bro-events-via-broccoli-api/774>\
**Category:** Zeek\
**Created:** [June 15, 2005, 9:48pm UTC](https://community.zeek.org/t/receiving-bro-events-via-broccoli-api/774 "2005-06-15T21:48:46Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mike\_Muratet](https://avatars.discourse-cdn.com/v4/letter/m/eb9ed0/32.png) [@Mike\_Muratet](https://community.zeek.org/u/Mike_Muratet)\
**Post date:** [June 15, 2005, 9:48pm UTC](https://community.zeek.org/t/receiving-bro-events-via-broccoli-api/774/1 "2005-06-15T21:48:46Z")

</div>

Greetings

I don't know why I've had such poor like with 'broping' (and thanks to Christian for all his help) but I have been successful receiving the predefined events in conn.bro. However, the compiler is complaining about the call-back function argument in my interface: "passing arg 3 of 'bro\_event\_registry\_add' from incompatible pointer type". I have tried to type this as void and as BroEventFunc with the same results. I haven't found much that's helpful searching the Internet, can anybody clue me in about what's going on?

The events in conn.bro have 'connection' objects as their parameters. As I understand the manuals, I can get the fields out of the object with the bro\_record\_get\_xxxx methods?

Thanks

Mike

---

<div class="post-metadata">

**Author:** ![Stefan\_Kornexl](https://avatars.discourse-cdn.com/v4/letter/s/bbce88/32.png) [@Stefan\_Kornexl](https://community.zeek.org/u/Stefan_Kornexl)\
**Post date:** [June 16, 2005, 6:47am UTC](https://community.zeek.org/t/receiving-bro-events-via-broccoli-api/774/2 "2005-06-16T06:47:11Z")

</div>

Hi Mike,

> However, the compiler is complaining about  
> the call-back function argument in my interface: "passing arg 3 of  
> 'bro\_event\_registry\_add' from incompatible pointer type". I have tried to  
> type this as void and as BroEventFunc with the same results.

The return type of the function should be void:

void your\_callback\_func(BroConn\* bc, ...) { ... }

Not to confuse with that, the 3rd argument to bro\_event\_registry\_add()  
is expected to be of BroEventFunc. In order to cast your function  
accordingly when passing it, you can do:

bro\_event\_registry\_add(bc, "your\_event\_name",  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;(BroEventFunc)your\_callback\_func);

> The events in conn.bro have 'connection' objects as their parameters. As I  
> understand the manuals, I can get the fields out of the object with the  
> bro\_record\_get\_xxxx methods?

Your callback function needs to have a BroRecord\* as one of its  
arguments at the appropriate position, and yes, then you can use the  
bro\_record\_get\_xxxx functions to access the fields in that record  
passed to your callback when the event arrives.

-- Stefan

---

<div class="post-metadata">

**Author:** ![Mike\_Muratet](https://avatars.discourse-cdn.com/v4/letter/m/eb9ed0/32.png) [@Mike\_Muratet](https://community.zeek.org/u/Mike_Muratet)\
**Post date:** [June 16, 2005, 1:51pm UTC](https://community.zeek.org/t/receiving-bro-events-via-broccoli-api/774/3 "2005-06-16T13:51:49Z")

</div>

Stefan

> > However, the compiler is complaining about  
> > the call-back function argument in my interface: "passing arg 3 of  
> > 'bro\_event\_registry\_add' from incompatible pointer type". I have tried to  
> > type this as void and as BroEventFunc with the same results.
> 
> The return type of the function should be void:
> 
> void your\_callback\_func(BroConn\* bc, ...) { ... }
> 
> Not to confuse with that, the 3rd argument to bro\_event\_registry\_add()  
> is expected to be of BroEventFunc. In order to cast your function  
> accordingly when passing it, you can do:
> 
> bro\_event\_registry\_add(bc, "your\_event\_name",  
> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;(BroEventFunc)your\_callback\_func);

Doh. I completely forgot about the trick. Thanks.

> > The events in conn.bro have 'connection' objects as their parameters. As I  
> > understand the manuals, I can get the fields out of the object with the  
> > bro\_record\_get\_xxxx methods?
> 
> Your callback function needs to have a BroRecord\* as one of its  
> arguments at the appropriate position, and yes, then you can use the  
> bro\_record\_get\_xxxx functions to access the fields in that record  
> passed to your callback when the event arrives.

I'll give that a shot. Thanks again.

Cheers

Mike

---

<div class="post-metadata">

**Author:** ![Christian\_Kreibich3](https://avatars.discourse-cdn.com/v4/letter/c/4af34b/32.png) [@Christian\_Kreibich3](https://community.zeek.org/u/Christian_Kreibich3)\
**Post date:** [June 16, 2005, 6:25pm UTC](https://community.zeek.org/t/receiving-bro-events-via-broccoli-api/774/4 "2005-06-16T18:25:42Z")

</div>

Yeah, exactly. Note that connection records are rather complex to handle  
at the Broccoli level because they contain nested records, so it may  
require a bit of work to get to the fields you're interested in. Just  
follow the structure laid out in bro.init.

Cheers,  
Christian.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:37pm UTC](https://community.zeek.org/t/receiving-bro-events-via-broccoli-api/774/5 "2022-05-06T15:37:30Z")

</div>


