# using broccoli to send events to bro

**URL:** <https://community.zeek.org/t/using-broccoli-to-send-events-to-bro/2828>\
**Category:** Zeek\
**Created:** [September 24, 2013, 1:20am UTC](https://community.zeek.org/t/using-broccoli-to-send-events-to-bro/2828 "2013-09-24T01:20:09Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mike\_Sconzo](https://avatars.discourse-cdn.com/v4/letter/m/d6d6ee/32.png) [@Mike\_Sconzo](https://community.zeek.org/u/Mike_Sconzo)\
**Post date:** [September 24, 2013, 1:20am UTC](https://community.zeek.org/t/using-broccoli-to-send-events-to-bro/2828/1 "2013-09-24T01:20:09Z")

</div>

I've got a .bro file that looks like:

module A;  
global f: file = open("wtf.txt");  
redef Communication::nodes += {  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;["test"] = [$host = 127.0.0.1, $events = /test1/],  
};  
event test1(a: string)  
&nbsp;&nbsp;&nbsp;&nbsp;{  
&nbsp;&nbsp;&nbsp;&nbsp;print f, "got here";  
&nbsp;&nbsp;&nbsp;&nbsp;}

and a python script that looks like:  
#! /usr/bin/python

from broccoli import \*

bc = Connection("127.0.0.1:47761")  
bc.send("test1", "aaaaaaaaaaaaaaaa")  
bc.processInput();  
print "done"

I get the following log messages:  
1379985413.067179 manager child - - - info  
[#10005/127.0.0.1:34609] accepted clear connection  
1379985413.068412 manager parent - - - info  
[#10005/127.0.0.1:34609] added peer  
1379985413.068412 manager parent - - - info  
[#10005/127.0.0.1:34609] peer connected  
1379985413.068412 manager parent - - - info  
[#10005/127.0.0.1:34609] phase: version  
1379985413.068412 manager script - - - info  
connection established  
1379985413.068412 manager script - - - info  
requesting events matching /^?(test1)$?/  
1379985413.068412 manager script - - - info  
accepting state  
1379985413.069943 manager parent - - - info  
[#10005/127.0.0.1:34609] phase: handshake  
1379985413.270825 manager parent - - - info  
[#10005/127.0.0.1:34609] peer does not support 64bit PIDs; using  
compatibility mode  
1379985413.270825 manager parent - - - info  
[#10005/127.0.0.1:34609] peer is a Broccoli  
1379985413.270825 manager parent - - - info  
[#10005/127.0.0.1:34609] phase: running  
1379985413.270825 manager script - - - info  
connection closed  
1379985413.272093 manager parent - - - info  
[#10005/127.0.0.1:34609] peer disconnected  
1379985413.273243 manager child - - - info  
[#10005/127.0.0.1:34609] connection closed  
1379985413.851595 worker-1 child - - -  
info selects=3100000 canwrites=0 timeouts=3098508  
1379985416.921436 manager child - - - info  
selects=3200000 canwrites=0 timeouts=3198460  
1379985411.837037 proxy-1 child - - - info  
selects=3100000 canwrites=0 timeouts=30999

But nothing gets persisted to the "wtf.txt" file. I'm sure (I hope)  
I'm missing something super easy. Any ideas?

Thanks!

---

<div class="post-metadata">

**Author:** ![Siwek\_Jon](https://avatars.discourse-cdn.com/v4/letter/s/90db22/32.png) [@Siwek\_Jon](https://community.zeek.org/u/Siwek_Jon)\
**Post date:** [September 24, 2013, 2:44pm UTC](https://community.zeek.org/t/using-broccoli-to-send-events-to-bro/2828/2 "2013-09-24T14:44:14Z")

</div>

processInput() doesn't guarantee that any events are actually processed. It returns True if the send-queue is non-empty so calling it in a loop to make sure the event is sent is probably what you want:

&nbsp;&nbsp;&nbsp;&nbsp;while bc.processInput():  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;pass # or sleep or do other stuff

- Jon

---

<div class="post-metadata">

**Author:** ![Mike\_Sconzo](https://avatars.discourse-cdn.com/v4/letter/m/d6d6ee/32.png) [@Mike\_Sconzo](https://community.zeek.org/u/Mike_Sconzo)\
**Post date:** [September 24, 2013, 3:12pm UTC](https://community.zeek.org/t/using-broccoli-to-send-events-to-bro/2828/3 "2013-09-24T15:12:49Z")

</div>

Thanks that's good to know. I changed it to

while bc.processInput():  
&nbsp;&nbsp;&nbsp;&nbsp;sleep(2)

and it still seems to exit immediately.

Any additional thoughts? I'm pretty lost on this one. I'm using 2.1  
with the broccoli.py included with it.

Thanks again.

---

<div class="post-metadata">

**Author:** ![Siwek\_Jon](https://avatars.discourse-cdn.com/v4/letter/s/90db22/32.png) [@Siwek\_Jon](https://community.zeek.org/u/Siwek_Jon)\
**Post date:** [September 24, 2013, 4:35pm UTC](https://community.zeek.org/t/using-broccoli-to-send-events-to-bro/2828/4 "2013-09-24T16:35:46Z")

</div>

> Any additional thoughts? I'm pretty lost on this one. I'm using 2.1  
> with the broccoli.py included with it.

If output to the "wtf.txt" file is buffered, you probably aren't going to see anything in there right away. Maybe not even until you terminate the bro process since there's so little data. You can put a regular print statement to stdout in the event handler in your bro script to verify you actually get events, but nothing has yet been written to disk. You could also have your python script send a whole bunch of events and hope you actually cause output to be flushed.

- Jon

---

<div class="post-metadata">

**Author:** ![Mike\_Sconzo](https://avatars.discourse-cdn.com/v4/letter/m/d6d6ee/32.png) [@Mike\_Sconzo](https://community.zeek.org/u/Mike_Sconzo)\
**Post date:** [September 24, 2013, 6:07pm UTC](https://community.zeek.org/t/using-broccoli-to-send-events-to-bro/2828/5 "2013-09-24T18:07:46Z")

</div>

-1 for me. It was a buffering problem (sending 1000 events worked quite well).

Thanks for the assistance, I feel "special".

-=Mike

---

<div class="post-metadata">

**Author:** ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)\
**Post date:** [September 24, 2013, 8:36pm UTC](https://community.zeek.org/t/using-broccoli-to-send-events-to-bro/2828/6 "2013-09-24T20:36:17Z")

</div>

Actually I'm not sure if processInput() returns true if there's  
something in \*send\* queue (as opposed to the receive queue). There  
might still be a race condition there. Does it work with an infite  
loop:

&nbsp;&nbsp;&nbsp;&nbsp;while True:  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;bc.processInput():  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;sleep(1)

Often the most reliable way to get such stuff working is sending an  
acknowledge event back and only terminating once that has been  
received.

Robin

---

<div class="post-metadata">

**Author:** ![Siwek\_Jon](https://avatars.discourse-cdn.com/v4/letter/s/90db22/32.png) [@Siwek\_Jon](https://community.zeek.org/u/Siwek_Jon)\
**Post date:** [September 24, 2013, 10:37pm UTC](https://community.zeek.org/t/using-broccoli-to-send-events-to-bro/2828/7 "2013-09-24T22:37:00Z")

</div>

> Actually I'm not sure if processInput() returns true if there's  
> something in \*send\* queue (as opposed to the receive queue).

If it doesn't, there's a couple code comments in broccoli/bindings that need fixing 🙂

- Jon

---

<div class="post-metadata">

**Author:** ![Mike\_Sconzo](https://avatars.discourse-cdn.com/v4/letter/m/d6d6ee/32.png) [@Mike\_Sconzo](https://community.zeek.org/u/Mike_Sconzo)\
**Post date:** [September 25, 2013, 2:10pm UTC](https://community.zeek.org/t/using-broccoli-to-send-events-to-bro/2828/8 "2013-09-25T14:10:08Z")

</div>

> > Actually I'm not sure if processInput() returns true if there's  
> > something in \*send\* queue (as opposed to the receive queue).

> If it doesn't, there's a couple code comments in broccoli/bindings that need fixing 🙂

That was my confusion exactly.

Regardless it seems to be working, I'm less concerned with termination  
of the python script and I'm entirely ok with waiting a while. I just  
wasn't getting any output and was confused.

Thanks again.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:41pm UTC](https://community.zeek.org/t/using-broccoli-to-send-events-to-bro/2828/9 "2022-05-06T15:41:15Z")

</div>


