# tcp contents

**URL:** <https://community.zeek.org/t/tcp-contents/634>\
**Category:** Zeek\
**Created:** [November 29, 2004, 9:37pm UTC](https://community.zeek.org/t/tcp-contents/634 "2004-11-29T21:37:27Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vern](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/vern/32/630_2.png) [@Vern](https://community.zeek.org/u/Vern)\
**Post date:** [November 29, 2004, 9:37pm UTC](https://community.zeek.org/t/tcp-contents/634/1 "2004-11-29T21:37:27Z")

</div>

> In short, this is what I'm trying to do: I want to selectively save  
> the payload/contents of a TCP stream to a file just based on the  
> protocol/port number.

If you want to do this offline processing a trace, then it's very  
easy - just "bro -f 'tcp port 80 or tcp port 25' -r trace contents",  
for example.

If you want todo it online while also doing other work, then a  
natural way would be something like:

&nbsp;&nbsp;global interesting\_services = { smtp, http, };

&nbsp;&nbsp;event connection\_established(c: connection)  
&nbsp;&nbsp;&nbsp;&nbsp;{  
&nbsp;&nbsp;&nbsp;&nbsp;if ( c$id$resp\_p in interesting\_services )  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;demux\_conn(c$id, "interesting", "orig", "resp");  
&nbsp;&nbsp;&nbsp;&nbsp;}

(with the caveat that I haven't tested this)

&nbsp;&nbsp;&nbsp;&nbsp;Vern

---

<div class="post-metadata">

**Author:** ![john\_mcnicholas](https://avatars.discourse-cdn.com/v4/letter/j/fbc32d/32.png) [@john\_mcnicholas](https://community.zeek.org/u/john_mcnicholas)\
**Post date:** [November 30, 2004, 2:45am UTC](https://community.zeek.org/t/tcp-contents/634/2 "2004-11-30T02:45:54Z")

</div>

> If you want todo it online while also doing other work, then a  
> natural way would be something like:
> 
> global interesting\_services = { smtp, http, };
> 
> event connection\_established(c: connection)  
> &nbsp;&nbsp;{  
> &nbsp;&nbsp;if ( c$id$resp\_p in interesting\_services )  
> &nbsp;&nbsp;&nbsp;&nbsp;demux\_conn(c$id, "interesting", "orig", "resp");  
> &nbsp;&nbsp;}
> 
> (with the caveat that I haven't tested this)

Thanks for the tip.

Good news: I went ahead and tested it and it worked fine when saving the  
contents to 2 separate files.  
Bad news: Although it took just a simple modification to a copy of  
"demunx\_conn()", I couldn't get it to work when writing to 1 file by using  
the CONTENTS\_BOTH flag.

Assuming the above observations are true, then unless someone can state why  
CONTENTS\_BOTH has problems I will go ahead and continue investigating  
tomorrow.

More details on the "bad news":

- at a minimum the data is not ordered properly. this is readily apparent  
when examining the POP3 protocol when there isn't any mail to deliver.  
perhaps it is as simple as the data being cached and then flushed? (I'm now  
suspicious of this, and will look at it tomorrow. sorry for the premature  
post.)

- for HTTP it also appeared the data was not properly ordered. i can't say  
for certain but it appeared that the first "get" was frequently missing  
while the response was properly added.

- two workarounds for the above were to either  
the empty "events" for those analyzers (correct term?)  
&nbsp;&nbsp;b: instantiating the TCP\_TransactionContents class for HTTP, SMTP,  
and POP3. The simple class seems to flush the data properly.

Perhaps I'm swimming upstream by trying to use the single file approach, but  
it really does seem doable.

Thanks for the help.

John

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:37pm UTC](https://community.zeek.org/t/tcp-contents/634/3 "2022-05-06T15:37:15Z")

</div>


