# Using Bro IDS in offline analysis

**URL:** <https://community.zeek.org/t/using-bro-ids-in-offline-analysis/1583>\
**Category:** Zeek\
**Created:** [February 12, 2010, 3:36pm UTC](https://community.zeek.org/t/using-bro-ids-in-offline-analysis/1583 "2010-02-12T15:36:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ssm\_as](https://avatars.discourse-cdn.com/v4/letter/s/e19b73/32.png) [@ssm\_as](https://community.zeek.org/u/ssm_as)\
**Post date:** [February 12, 2010, 3:36pm UTC](https://community.zeek.org/t/using-bro-ids-in-offline-analysis/1583/1 "2010-02-12T15:36:38Z")

</div>

> Hello,  
>   
> Finally, I installed bro IDS (1.5.1) on my Ubuntu(9.10) machine. Of course, that after the useful information I got from this mailing list. Thanks you all  
>   
> So after:  
> ./configure  
> make  
> make install-broctl  
>   
> I did not do nay sort of configuration this because I am not sure what should I do.  
> I do not want to use Bro for intrusion detection in real time. I am more interested in using it in forensics and intrusion analysis.  
>   
> Shortly, I have several network binary file is PCAP and TCPDUMP format. I want to parse these files with Bro and get the bro alerts in machine readab;e format (txt, csv, or whaterver).  
>   
> 1- Is that possible ( Usually I use snort and it is very easy to accomplish but I am planning to compare between Snort and Bro)?  
>   
> 2- What are the configurations that I need?  
>   
> Thanks,  
> Sherif Saad  
>   
>   
>   
>   
>   
>   
> |

---

<div class="post-metadata">

**Author:** ![Justin\_Azoff](https://avatars.discourse-cdn.com/v4/letter/j/eb9ed0/32.png) [@Justin\_Azoff](https://community.zeek.org/u/Justin_Azoff)\
**Post date:** [February 12, 2010, 4:54pm UTC](https://community.zeek.org/t/using-bro-ids-in-offline-analysis/1583/2 "2010-02-12T16:54:03Z")

</div>

> Shortly, I have several network binary file is PCAP and TCPDUMP format. I  
> want to parse these files with Bro and get the bro alerts in machine readab;e  
> format (txt, csv, or whaterver).
> 
> 1- Is that possible ( Usually I use snort and it is very easy to accomplish  
> but I am planning to compare between Snort and Bro)?

Definitely!

> 2- What are the configurations that I need?

Not much...  
&nbsp;&nbsp;&nbsp;&nbsp;  
&nbsp;&nbsp;&nbsp;&nbsp;bro -f 'ip' -C -r your.pcap brolite

will run 'your.pcap' through bro while loading the brolite policy(which loads most things)  
you could run it through specific policies by just running something like

&nbsp;&nbsp;&nbsp;&nbsp;bro -f 'ip' -C -r your.pcap http-request smtp irc

That should get you started.. you'll probably want to start writing your own  
policy scripts to detect the specific things you are looking for and output  
them in the format you want.

---

<div class="post-metadata">

**Author:** ![Vern](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/vern/32/630_2.png) [@Vern](https://community.zeek.org/u/Vern)\
**Post date:** [February 14, 2010, 7:22pm UTC](https://community.zeek.org/t/using-bro-ids-in-offline-analysis/1583/3 "2010-02-14T19:22:53Z")

</div>

> &nbsp;&nbsp;&nbsp;&nbsp;bro -f 'ip' -C -r your.pcap brolite
> 
> will run 'your.pcap' through bro while loading the brolite policy(which loads most things)

Yep. A minor nit: you shouldn't need "-f ip", as analysis scripts generally  
include a tcpdump filter for the packets of interest; and you shouldn't  
need -C \*unless\* the capture has bad checksums (which is usually not the  
case, but can be for systems that are recording their own traffic, for  
example).

&nbsp;&nbsp;&nbsp;&nbsp;Vern

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:39pm UTC](https://community.zeek.org/t/using-bro-ids-in-offline-analysis/1583/4 "2022-05-06T15:39:02Z")

</div>


