# Replacing the &synchronized attribute in 2.6

**URL:** <https://community.zeek.org/t/replacing-the-synchronized-attribute-in-2-6/5634>\
**Category:** Zeek\
**Created:** [March 14, 2019, 9:43am UTC](https://community.zeek.org/t/replacing-the-synchronized-attribute-in-2-6/5634 "2019-03-14T09:43:18Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Michal\_Purzynski1](https://avatars.discourse-cdn.com/v4/letter/m/a88e57/32.png) [@Michal\_Purzynski1](https://community.zeek.org/u/Michal_Purzynski1)\
**Post date:** [March 14, 2019, 9:43am UTC](https://community.zeek.org/t/replacing-the-synchronized-attribute-in-2-6/5634/1 "2019-03-14T09:43:18Z")

</div>

Hey,

do we have any example how to replace the old &synchronized attribute in the new Broker-powered world? I looked at the documentation (it’s extremely verbose) and found nothing that I could relate to.

Here is the pattern I’m trying to port to 2.6. It’s basically a code that uses the Input Framework, reads some lists, stores them in a simple set and keeps this set synchronized.  
The problem might be coming from a not obvious behavior of the &synchronized attribute - I had no idea what it did, I knew that it was supposed to be there.

The old 2.5.5 documentation mentions this attribute briefly  
[https://docs.zeek.org/en/stable/script-reference/attributes.html](https://docs.zeek.org/en/stable/script-reference/attributes.html)

&synchronized - synchronize a variable across nodes ← what nodes are we talking about? what’s the communication flow here? Who is the producer, who is the consumer?  
It is impossible to move my scripts over to Broker without answering those questions.

type Idx: record {  
whitelist\_ip: subnet;  
};

global whitelist\_scan\_ip: set[subnet] = {} **&synchronized** ; ← the boo-boo is here

event bro\_init()  
{  
Input::add\_table([$source=“scan\_ip.txt”,  
$name=“whitelist\_scan\_ip”,  
$idx=Idx,  
$destination=whitelist\_scan\_ip,  
$mode=Input::REREAD]);  
}

---

<div class="post-metadata">

**Author:** ![Jan](https://avatars.discourse-cdn.com/v4/letter/j/ce7236/32.png) [@Jan](https://community.zeek.org/u/Jan)\
**Post date:** [March 14, 2019, 10:02am UTC](https://community.zeek.org/t/replacing-the-synchronized-attribute-in-2-6/5634/2 "2019-03-14T10:02:35Z")

</div>

[https://docs.zeek.org/en/stable/frameworks/broker.html#porting-guide](https://docs.zeek.org/en/stable/frameworks/broker.html#porting-guide)

I guess data stores are the way to go.  
Jan

---

<div class="post-metadata">

**Author:** ![Hosom\_Stephen\_M](https://avatars.discourse-cdn.com/v4/letter/h/d26b3c/32.png) [@Hosom\_Stephen\_M](https://community.zeek.org/u/Hosom_Stephen_M)\
**Post date:** [March 14, 2019, 12:58pm UTC](https://community.zeek.org/t/replacing-the-synchronized-attribute-in-2-6/5634/3 "2019-03-14T12:58:32Z")

</div>

Michal,

For the use case in your email, the best option available to you is the Configuration Framework.

[https://docs.zeek.org/en/stable/frameworks/configuration.html](https://docs.zeek.org/en/stable/frameworks/configuration.html)

# First file:

module TestModule;

export {

option whitelist\_scan\_ip: set[subnet] = {};

redef Config::config\_files += { "/path/to/my/config.dat" };

}

# /path/to/my/config.dat:

TestModule::whitelist\_scan\_ip = 10.1.2.0/24,10.1.3.0/24,10.1.4.0/24

Thanks,

Stephen

---

<div class="post-metadata">

**Author:** ![Michal\_Purzynski1](https://avatars.discourse-cdn.com/v4/letter/m/a88e57/32.png) [@Michal\_Purzynski1](https://community.zeek.org/u/Michal_Purzynski1)\
**Post date:** [March 14, 2019, 6:15pm UTC](https://community.zeek.org/t/replacing-the-synchronized-attribute-in-2-6/5634/4 "2019-03-14T18:15:55Z")

</div>

Thanks, using the configuration framework is easier indeed.

Just for the sake of discussing some broker code - do we have examples how people replace the &synchronized attribute?

---

<div class="post-metadata">

**Author:** ![Samuel\_Oehlert](https://avatars.discourse-cdn.com/v4/letter/s/e9a140/32.png) [@Samuel\_Oehlert](https://community.zeek.org/u/Samuel_Oehlert)\
**Post date:** [March 14, 2019, 6:25pm UTC](https://community.zeek.org/t/replacing-the-synchronized-attribute-in-2-6/5634/5 "2019-03-14T18:25:11Z")

</div>

Mike Dopheide wrote a blog post (on the Zeek blog) about that exact topic not too long ago. He had spent a lot of time at work fixing a bug with one of our policies and had this deep dive in the process. It’s a good read.

[https://blog.zeek.org/2018/07/broker-is-coming-part-2-replacing.html](https://blog.zeek.org/2018/07/broker-is-coming-part-2-replacing.html)

- Sam

---

<div class="post-metadata">

**Author:** ![Michal\_Purzynski1](https://avatars.discourse-cdn.com/v4/letter/m/a88e57/32.png) [@Michal\_Purzynski1](https://community.zeek.org/u/Michal_Purzynski1)\
**Post date:** [March 15, 2019, 2:42am UTC](https://community.zeek.org/t/replacing-the-synchronized-attribute-in-2-6/5634/6 "2019-03-15T02:42:56Z")

</div>

Thanks - this is exactly what I was Googling for (and could not find).

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:46pm UTC](https://community.zeek.org/t/replacing-the-synchronized-attribute-in-2-6/5634/7 "2022-05-06T15:46:23Z")

</div>


