# TCP connection summaries

**URL:** <https://community.zeek.org/t/tcp-connection-summaries/2838>\
**Category:** Zeek\
**Created:** [September 28, 2013, 1:07pm UTC](https://community.zeek.org/t/tcp-connection-summaries/2838 "2013-09-28T13:07:45Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Laleh\_Arshadi](https://avatars.discourse-cdn.com/v4/letter/l/6f9a4e/32.png) [@Laleh\_Arshadi](https://community.zeek.org/u/Laleh_Arshadi)\
**Post date:** [September 28, 2013, 1:07pm UTC](https://community.zeek.org/t/tcp-connection-summaries/2838/1 "2013-09-28T13:07:45Z")

</div>

Hi all

I see that you can get a connection summary log of an offline pcap traffic file by running bro with a simple command line as:  
bro -r traffic\_file\_name  
I have tested this command and it works well. But I am only interested in TCP connection summaries so I tried:  
bro -r traffic\_file\_name tcp  
But I get an error indication ‘tcp’ as unkown. What have I missed here?

Regards  
L. Arshadi

---

<div class="post-metadata">

**Author:** ![Jon\_Schipp](https://avatars.discourse-cdn.com/v4/letter/j/8797f3/32.png) [@Jon\_Schipp](https://community.zeek.org/u/Jon_Schipp)\
**Post date:** [September 28, 2013, 3:00pm UTC](https://community.zeek.org/t/tcp-connection-summaries/2838/2 "2013-09-28T15:00:47Z")

</div>

To pass a BPF try ``-f tcp’’

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:41pm UTC](https://community.zeek.org/t/tcp-connection-summaries/2838/3 "2022-05-06T15:41:16Z")

</div>


