# Unable to generate intel.log

**URL:** <https://community.zeek.org/t/unable-to-generate-intel-log/7955>\
**Category:** Zeek\
**Created:** [March 12, 2026, 1:33pm UTC](https://community.zeek.org/t/unable-to-generate-intel-log/7955 "2026-03-12T13:33:30Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![johanna](https://avatars.discourse-cdn.com/v4/letter/j/50afbb/32.png) [@johanna](https://community.zeek.org/u/johanna)\
**Post date:** [March 12, 2026, 4:52pm UTC](https://community.zeek.org/t/unable-to-generate-intel-log/7955/2 "2026-03-12T16:52:30Z")

</div>

Hi,

there are a couple of possible cases for this to happen. The first one is that, when processing pcaps, there always is a bit of a race condition between the input framework and the pcap processing. Both happen simultaneously - and pcap processing (for small pcaps) often is faster.

You can load a short script that suspends processing till after the intelligence file is loaded, e.g. like this:

```auto
event zeek_init()
        {
        suspend_processing();
        }

event Input::end_of_data(name: string, source: string)
        {
        if ( /^intel-/ in name )
                continue_processing();
        }

```

The second possibility is that only a quic connection is established (via udp). UDP connections don’t automatically trigger the intelligence framework.

---

_[View the full topic](https://community.zeek.org/t/unable-to-generate-intel-log/7955)._
