# Store PCAP logs

**URL:** <https://community.zeek.org/t/store-pcap-logs/3748>\
**Category:** Zeek\
**Created:** [August 3, 2015, 1:14pm UTC](https://community.zeek.org/t/store-pcap-logs/3748 "2015-08-03T13:14:36Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![user8](https://avatars.discourse-cdn.com/v4/letter/u/f1d935/32.png) [@user8](https://community.zeek.org/u/user8)\
**Post date:** [August 3, 2015, 1:14pm UTC](https://community.zeek.org/t/store-pcap-logs/3748/1 "2015-08-03T13:14:36Z")

</div>

Hello,

I’ve installed Bro IDS on my computer, and I want to know is it possible to make Bro generate pcap logs? Because I want to use Wireshark to analyze Bro logs.  
Another question, does anyone tried Splunk to analyze Bro logs? Can anyone give me some advice?

Any help would be great. Thank You.

---

<div class="post-metadata">

**Author:** ![Slagell\_Adam\_J](https://avatars.discourse-cdn.com/v4/letter/s/e9c0ed/32.png) [@Slagell\_Adam\_J](https://community.zeek.org/u/Slagell_Adam_J)\
**Post date:** [August 3, 2015, 1:30pm UTC](https://community.zeek.org/t/store-pcap-logs/3748/2 "2015-08-03T13:30:38Z")

</div>

Bro can analyze pcaps, but it doesn't generate them.

Wire shark isn't really a log analyzer, but a raw traffic analyzer/GUI.

There are Bro plugins for Splunk. It works well.

---

<div class="post-metadata">

**Author:** ![Daniel\_Thayer](https://avatars.discourse-cdn.com/v4/letter/d/8dc957/32.png) [@Daniel\_Thayer](https://community.zeek.org/u/Daniel_Thayer)\
**Post date:** [August 3, 2015, 5:06pm UTC](https://community.zeek.org/t/store-pcap-logs/3748/3 "2015-08-03T17:06:28Z")

</div>

Bro can generate pcap files with the "-w" command-line option.  
Example:  
bro -i eth0 -w output.pcap

---

<div class="post-metadata">

**Author:** ![Slagell\_Adam\_J](https://avatars.discourse-cdn.com/v4/letter/s/e9c0ed/32.png) [@Slagell\_Adam\_J](https://community.zeek.org/u/Slagell_Adam_J)\
**Post date:** [August 3, 2015, 5:18pm UTC](https://community.zeek.org/t/store-pcap-logs/3748/4 "2015-08-03T17:18:08Z")

</div>

Keep in mind that you aren't analyzing Bro logs in this way, though. If all you want are pcaps, tcpdump should suffice. If you want both, this is a good solution.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:42pm UTC](https://community.zeek.org/t/store-pcap-logs/3748/5 "2022-05-06T15:42:56Z")

</div>


