Hi Izik,

in share/bro/policy/protocols/smb/main.smb

look for write_cmd_log =F, if you change it to T, it will start the printing.

good luck


As a small addendum; that log probably isn't very useful. It was mostly created to be used during development because it logs every single SMB cmd that is seen (and there are *lots* of SMB cmd messages sent around).