# Using create\_expire and expire\_func

**URL:** <https://community.zeek.org/t/using-create-expire-and-expire-func/2279>\
**Category:** Zeek\
**Created:** [April 6, 2012, 6:41am UTC](https://community.zeek.org/t/using-create-expire-and-expire-func/2279 "2012-04-06T06:41:36Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sheharbano\_Khattak](https://avatars.discourse-cdn.com/v4/letter/s/958977/32.png) [@Sheharbano\_Khattak](https://community.zeek.org/u/Sheharbano_Khattak)\
**Post date:** [April 6, 2012, 6:41am UTC](https://community.zeek.org/t/using-create-expire-and-expire-func/2279/1 "2012-04-06T06:41:36Z")

</div>

Dear Bro Team,

I have a global table that i populate at the time of initialization (bro\_init). I want to empty it every x minutes to fill it up with fresh values. This means that i also need to be notified when the table is being emptied. It seems to me that the attributes &create\_expire and &expire\_func will be helpful for my requirements. I wrote a quick script to check if the behavior matches my expectation. However, it doesn’t seems to work as expected. Here is my script:

in try.bro:

---

<div class="post-metadata">

**Author:** ![Vern](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/vern/32/630_2.png) [@Vern](https://community.zeek.org/u/Vern)\
**Post date:** [April 6, 2012, 6:53pm UTC](https://community.zeek.org/t/using-create-expire-and-expire-func/2279/2 "2012-04-06T18:53:26Z")

</div>

> &nbsp;&nbsp;&nbsp;&nbsp;print s;
> 
> &nbsp;&nbsp;&nbsp;&nbsp;sleep(15);
> 
> &nbsp;&nbsp;&nbsp;&nbsp;#s should be empty  
> &nbsp;&nbsp;&nbsp;&nbsp;print s;  
> }  
> ----------------------------------------------------------------------------  
> in bro.bif  
> -----------------------------------------------------------------------------  
> function sleep%(time\_secs: count%): any  
> &nbsp;&nbsp;&nbsp;&nbsp;%{  
> &nbsp;&nbsp;&nbsp;&nbsp;usleep(time\_secs \* 1000000);  
> &nbsp;&nbsp;&nbsp;&nbsp;return 0;  
> &nbsp;&nbsp;&nbsp;&nbsp;%}
> 
> ...
> 
> Why isn't 's' empty on second print?

Bro drives its evaluation of timers based on the clock advancing between  
events. The above code sequence doesn't include any subsequent event after  
bro\_init(), so the expiration timers don't have a chance to run.

&nbsp;&nbsp;&nbsp;&nbsp;Vern

---

<div class="post-metadata">

**Author:** ![Siwek\_Jon](https://avatars.discourse-cdn.com/v4/letter/s/90db22/32.png) [@Siwek\_Jon](https://community.zeek.org/u/Siwek_Jon)\
**Post date:** [April 6, 2012, 6:55pm UTC](https://community.zeek.org/t/using-create-expire-and-expire-func/2279/3 "2012-04-06T18:55:20Z")

</div>

Hi Sheharbano,

I inlined some notes:

> in try.bro:  
> -----------------------------------------------------------------------------  
> function inform\_me(s: set[string], idx: any): interval  
> {  
> &nbsp;&nbsp;&nbsp;&nbsp;print "expired";  
> &nbsp;&nbsp;&nbsp;&nbsp;return 5secs;  
> }

The return value of an &expire\_func indicates the amount of additional time to wait before expiring the element. So always returning "5secs" will never expire the element. Return "0secs" if you want the element removed automatically, or you could even "delete s[idx]" yourself.

> global s: set[string] &create\_expire=5secs &expire\_func=inform\_me;
> 
> event bro\_init()  
> {
> 
> &nbsp;&nbsp;&nbsp;&nbsp;add s["i"];  
> &nbsp;&nbsp;&nbsp;&nbsp;add s["am"];  
> &nbsp;&nbsp;&nbsp;&nbsp;add s["here"];
> 
> &nbsp;&nbsp;&nbsp;&nbsp;#s should have i,am,here  
> &nbsp;&nbsp;&nbsp;&nbsp;print s;
> 
> &nbsp;&nbsp;&nbsp;&nbsp;sleep(15);
> 
> &nbsp;&nbsp;&nbsp;&nbsp;#s should be empty  
> &nbsp;&nbsp;&nbsp;&nbsp;print s;  
> }  
> ----------------------------------------------------------------------------  
> in bro.bif  
> -----------------------------------------------------------------------------  
> function sleep%(time\_secs: count%): any  
> &nbsp;&nbsp;&nbsp;&nbsp;%{  
> &nbsp;&nbsp;&nbsp;&nbsp;usleep(time\_secs \* 1000000);  
> &nbsp;&nbsp;&nbsp;&nbsp;return 0;  
> &nbsp;&nbsp;&nbsp;&nbsp;%}

The sleep BIF you added doesn't look like it's enough to trigger the internal timers that Bro would use for table expiration, or at least I couldn't find a way, but reading input from a pcap file that captured traffic for longer than your expiration interval could allow you to test it. You could handle the "new\_connection" event and check the contents of your global table there.

I did find a bug for the case when reading input live from an interface that would prevent expiry of table values set in bro\_init(), for which I committed a fix in the git fastpath branch. Also in fastpath, I made a test script you could refer to: testing/btest/language/expire\_func.test.

+Jon

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:40pm UTC](https://community.zeek.org/t/using-create-expire-and-expire-func/2279/4 "2022-05-06T15:40:17Z")

</div>


