# Suppress\_for issues

**URL:** <https://community.zeek.org/t/suppress-for-issues/3140>\
**Category:** Zeek\
**Created:** [June 6, 2014, 12:35pm UTC](https://community.zeek.org/t/suppress-for-issues/3140 "2014-06-06T12:35:07Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sangdrax8](https://avatars.discourse-cdn.com/v4/letter/s/f07891/32.png) [@sangdrax8](https://community.zeek.org/u/sangdrax8)\
**Post date:** [June 6, 2014, 12:35pm UTC](https://community.zeek.org/t/suppress-for-issues/3140/1 "2014-06-06T12:35:07Z")

</div>

I am having some problems (or maybe misunderstanding) of how the suppression works. I haven’t changed my configuration file and it was working at one time. Now after upgrading to the master branch (I was on the heartbleed) it seems my suppression isn’t working as I understand it.

I have activated the SSL certificate checking as follows:

@load policy/protocols/ssl/expiring-certs.bro  
redef SSL::notify\_certs\_expiration = ALL\_HOSTS;

now when I watch my notice log, I am seeing what appear to be LOTS of notice logs for the same certificate. I thought that perhaps just the e-mails get suppressed, but after turning on e-mail notifications I get an e-mail for every notice. Plus my notice log is filling up rather quickly.

I know this probably won’t be very legible, but here is an example of just 2 of the notices I get from a single connection. They look exactly the same to me, and they have a time set for the suppression. I would have expected to only get one of these, but you can see the time stamp shows multiple notices happening very quickly.

#fields ts uid id.orig\_h id.orig\_p id.resp\_h id.resp\_p fuid file\_mime\_type file\_desc proto note msg sub src dst p n peer\_descr actions suppress\_for dropped remote\_location.country\_code remote\_location.region remote\_location.city remote\_location.latitude remote\_location.longitude

1402057564.658489 CW6Riz4smTIRpMxWq1 1.1.1.1 51255 2.2.2.2 5223 F6irMUcwkf1ZcbIok - - tcp SSL::Certificate\_Expired Certificate emailAddress=,CN=,OU=,O= - 1.1.1.1 2.2.2.2 5223 - bro1 Notice::ACTION\_LOG 86400.000000 F - - - - -

1402057564.660035 CW6Riz4smTIRpMxWq1 1.1.1.1 51255 2.2.2.2 5223 F6irMUcwkf1ZcbIok - - tcp SSL::Certificate\_Expired Certificate emailAddress=,CN=,OU=,O= - 1.1.1.1 2.2.2.2 5223 - bro1 Notice::ACTION\_LOG 86400.000000 F - - - - -

---

<div class="post-metadata">

**Author:** ![Josh\_Liburdi](https://avatars.discourse-cdn.com/v4/letter/j/df705f/32.png) [@Josh\_Liburdi](https://community.zeek.org/u/Josh_Liburdi)\
**Post date:** [June 6, 2014, 12:54pm UTC](https://community.zeek.org/t/suppress-for-issues/3140/2 "2014-06-06T12:54:19Z")

</div>

Looks to me like the $identifer field was dropped from those notices  
with the move to 2.3 ...

Bro 2.2:

else if ( cert$not\_valid\_after \< network\_time() )  
NOTICE([$note=Certificate\_Expired,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$conn=c, $suppress\_for=1day,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$msg=fmt("Certificate %s expired at %T", cert$subject,  
cert$not\_valid\_after),  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$identifier=cat(c$id$resp\_h, c$id$resp\_p, c$ssl$cert\_hash)]);

Bro 2.3:

else if ( cert$not\_valid\_after \< network\_time() )  
NOTICE([$note=Certificate\_Expired,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$conn=c, $suppress\_for=1day,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$msg=fmt("Certificate %s expired at %T", cert$subject,  
cert$not\_valid\_after),  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$fuid=fuid]);

That will break suppression.

-Josh

---

<div class="post-metadata">

**Author:** ![sangdrax8](https://avatars.discourse-cdn.com/v4/letter/s/f07891/32.png) [@sangdrax8](https://community.zeek.org/u/sangdrax8)\
**Post date:** [June 6, 2014, 1:03pm UTC](https://community.zeek.org/t/suppress-for-issues/3140/3 "2014-06-06T13:03:27Z")

</div>

I was just trying to move back from the heartbleed branch in git to the current “stable.” Should I be checking out something other than master to make the move back from the heartbleed branch to stable branch?

---

<div class="post-metadata">

**Author:** ![sangdrax8](https://avatars.discourse-cdn.com/v4/letter/s/f07891/32.png) [@sangdrax8](https://community.zeek.org/u/sangdrax8)\
**Post date:** [June 6, 2014, 2:55pm UTC](https://community.zeek.org/t/suppress-for-issues/3140/4 "2014-06-06T14:55:18Z")

</div>

For now, I have just added my own identifier back to the ssl check, so I can stay on master with the Heartbleed code. Maybe by the time I run another update from git this will have been fixed and losing my own changes will be irrelevant.

Thank you!

---

<div class="post-metadata">

**Author:** ![johanna](https://avatars.discourse-cdn.com/v4/letter/j/50afbb/32.png) [@johanna](https://community.zeek.org/u/johanna)\
**Post date:** [June 6, 2014, 4:51pm UTC](https://community.zeek.org/t/suppress-for-issues/3140/5 "2014-06-06T16:51:01Z")

</div>

Oh, yes, sorry, I probably did that on accident while moving to file IDs. I guess we should add the suppression back in, I will try to take a look at it later and hopefully it will be back in the 2.3 release...

Johanna

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:41pm UTC](https://community.zeek.org/t/suppress-for-issues/3140/6 "2022-05-06T15:41:50Z")

</div>


