# The tcp\_contents event was triggerred succesfully on try zeek website but reported errors locally

**URL:** <https://community.zeek.org/t/the-tcp-contents-event-was-triggerred-succesfully-on-try-zeek-website-but-reported-errors-locally/6945>\
**Category:** Zeek\
**Created:** [March 22, 2023, 3:58am UTC](https://community.zeek.org/t/the-tcp-contents-event-was-triggerred-succesfully-on-try-zeek-website-but-reported-errors-locally/6945 "2023-03-22T03:58:34Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mchen](https://avatars.discourse-cdn.com/v4/letter/m/bcef8e/32.png) [@mchen](https://community.zeek.org/u/mchen)\
**Post date:** [March 22, 2023, 3:58am UTC](https://community.zeek.org/t/the-tcp-contents-event-was-triggerred-succesfully-on-try-zeek-website-but-reported-errors-locally/6945/1 "2023-03-22T03:58:34Z")

</div>

Hello,

I’m attempting to retrieve TCP payloads through the “tcp\_contents” event, and I tried a simple demo script as below.

```zeek
# Redefine tcp_content_deliver_all_orig/resp to deliver all requests/responses
redef tcp_content_deliver_all_orig = T;
redef tcp_content_deliver_all_resp = T;

event tcp_contents(c: connection, is_orig: bool, seq: count, contents: string)
    {
    local end_point = is_orig ? "originator" : "responder";
    print fmt("TCP contents of connection %s (%s):", c$uid, end_point);
    print contents;
    }

```

The script ran successfully on the [https://try.bro.org](https://try.bro.org/) website with Zeek version `5.1.0` and the `exercise_traffic.pcap` file.

However, when I tried to run the same script locally using the command `zeek -r sample.pcap demo.zeek`, I received errors from Zeek as follows:

> error in ./demo.zeek, line 33 and /home/zeek/Workspace/zeek-5.2.0-rc2/share/zeek/base/bif/plugins/./Zeek\_TCP.events.bif.zeek, line 319: use of undeclared alternate prototype (event(c:connection; is\_orig:bool; contents:string;) and tcp\_contents)

I suspect that the `use of undeclared alternate prototype` error indicating the script requires some other dependent scripts to be loaded. I have tried to load some, but without success. I do not know the exact command that was run on the try.zeek website, so I wonder if could help to point out what the errors are.

Thank you!

---

<div class="post-metadata">

**Author:** ![Benjamin\_Bannier](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/benjamin_bannier/32/595_2.png) [@Benjamin\_Bannier](https://community.zeek.org/u/Benjamin_Bannier)\
**Post date:** [March 22, 2023, 6:49am UTC](https://community.zeek.org/t/the-tcp-contents-event-was-triggerred-succesfully-on-try-zeek-website-but-reported-errors-locally/6945/2 "2023-03-22T06:49:02Z")

</div>

Could you share the code you are actually running? The error message mentions an error on line 33 of `demo.zeek` while the snippet you posted has only 10 lines.

I suspect on line 33 in your actual file you use some other signature for `tcp_contents` since the error message mentions

```auto
event(c:connection; is_orig:bool; contents:string)

```

while `tcp_contents` in `base/bif/plugins/Zeek_TCP.events.bif.zeek` and the implementation you used in above snippet both have the signature

```auto
event(c: connection, is_orig: bool, seq: count, contents: string)

```

---

<div class="post-metadata">

**Author:** ![mchen](https://avatars.discourse-cdn.com/v4/letter/m/bcef8e/32.png) [@mchen](https://community.zeek.org/u/mchen)\
**Post date:** [March 22, 2023, 10:06am UTC](https://community.zeek.org/t/the-tcp-contents-event-was-triggerred-succesfully-on-try-zeek-website-but-reported-errors-locally/6945/3 "2023-03-22T10:06:51Z")

</div>

Thanks for letting me know! I double-checked and realized that the demo script I tried online was actually right, just like you mentioned. However, when tried to run it locally, I must have mistakenly typed the event’s signature. Your help is greatly appreciated!
