# Some BPF love....

**URL:** <https://community.zeek.org/t/some-bpf-love/2396>\
**Category:** Zeek\
**Created:** [August 8, 2012, 3:38pm UTC](https://community.zeek.org/t/some-bpf-love/2396 "2012-08-08T15:38:07Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tom\_OBrion](https://avatars.discourse-cdn.com/v4/letter/t/d07c76/32.png) [@Tom\_OBrion](https://community.zeek.org/u/Tom_OBrion)\
**Post date:** [August 8, 2012, 3:38pm UTC](https://community.zeek.org/t/some-bpf-love/2396/1 "2012-08-08T15:38:07Z")

</div>

Sent this off to the SecurityOnion group, but probably should have  
sent it here. Oopsy!

Anyway

Please....I know I must be doing something noobish...but man, I have  
tried it 15 ways to Sunday and no love.

editing: /nsm/bro/spool/policy/site/local.bro

added "redef cmd\_line\_bpf\_filter = "not src host ipaddress";

I want to tweak a tad more based on dst port, but need to at least get  
the filter working for the IP.

I then do a check/install/restart

I watch BRO dns.log for the for the IP I added and she shows up. What  
the heck am I missing?

Any help much appreciated.

---

<div class="post-metadata">

**Author:** ![Tyler\_Schoenke](https://avatars.discourse-cdn.com/v4/letter/t/6de8d8/32.png) [@Tyler\_Schoenke](https://community.zeek.org/u/Tyler_Schoenke)\
**Post date:** [August 9, 2012, 2:38pm UTC](https://community.zeek.org/t/some-bpf-love/2396/2 "2012-08-09T14:38:58Z")

</div>

I've only briefly tested SecurityOnion, but in vanilla Bro, you would  
add something like this to local.bro. That file is located under  
$BROHOME/share/bro/site.

redef restrict\_filters += { ["host exemptions"] = "not (host 4.2.2.2)" };

I don't know SecuritiyOnion's layout, but I don't think you want to add  
it under spool. That is typically where runtime files are created.

Tyler

---

<div class="post-metadata">

**Author:** ![Azoff\_Justin](https://avatars.discourse-cdn.com/v4/letter/a/5fc32e/32.png) [@Azoff\_Justin](https://community.zeek.org/u/Azoff_Justin)\
**Post date:** [August 9, 2012, 3:15pm UTC](https://community.zeek.org/t/some-bpf-love/2396/3 "2012-08-09T15:15:09Z")

</div>

Might also need

redef PacketFilter::all\_packets = F; # don't capture all packets

---

<div class="post-metadata">

**Author:** ![Tom\_OBrion](https://avatars.discourse-cdn.com/v4/letter/t/d07c76/32.png) [@Tom\_OBrion](https://community.zeek.org/u/Tom_OBrion)\
**Post date:** [August 9, 2012, 3:26pm UTC](https://community.zeek.org/t/some-bpf-love/2396/4 "2012-08-09T15:26:38Z")

</div>

Hey Tyler

Thanks, I was updating it in the spool folder based on the DOC I was  
reading out on the SO groups site. I thought it was wierd that I  
update in the spool location and not the share location. Maybe I was  
just reading it wrong in the DOC. I have been known to skin reading  
and not completely reading it fully. 🙂 Anyway, made the updates in  
the location you mentioned and it seems to be working. I am not using  
your syntax though, I am using this:

redef cmd\_line\_bpf\_filter = "not (host x.x.x.x)";

Worked like a champ. Now I will tweak to include dest port and should  
be good to go. Thanks man. Got me on the right track!

Tom

---

<div class="post-metadata">

**Author:** ![Doug\_Burks](https://avatars.discourse-cdn.com/v4/letter/d/ee7513/32.png) [@Doug\_Burks](https://community.zeek.org/u/Doug_Burks)\
**Post date:** [August 9, 2012, 3:33pm UTC](https://community.zeek.org/t/some-bpf-love/2396/5 "2012-08-09T15:33:27Z")

</div>

Thanks for finding this documentation bug! It is now fixed.

If I understand Seth correctly, we won't have to do this anymore in  
Bro 2.1 since it will just read our existing bpf.conf.

Thanks,  
Doug

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [August 10, 2012, 2:09am UTC](https://community.zeek.org/t/some-bpf-love/2396/6 "2012-08-10T02:09:55Z")

</div>

Thanks for pointing that out! That bit of poor design is unfortunately still going to remain for 2.1, but it will absolutely be gone for 2.2. I'll make sure that in the 2.2 release we have good examples for the new way of working with the packet filter framework.

For anyone making changes to your packet filter now, please keep your changes in one place so that it will be easier to upgrade to 2.2 when that time comes.

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [August 10, 2012, 2:12am UTC](https://community.zeek.org/t/some-bpf-love/2396/7 "2012-08-10T02:12:33Z")

</div>

I'll probably commit a script to a personal repository on github which you can then run on security onion for 2.1. I don't want to include in the 2.1 release since it will be a little hacky since the rewritten packet filter framework isn't going to be included yet.

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:40pm UTC](https://community.zeek.org/t/some-bpf-love/2396/8 "2022-05-06T15:40:29Z")

</div>


