# weird.log help

**URL:** <https://community.zeek.org/t/weird-log-help/4110>\
**Category:** Zeek\
**Created:** [April 14, 2016, 8:18pm UTC](https://community.zeek.org/t/weird-log-help/4110 "2016-04-14T20:18:22Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Josh\_Guild](https://avatars.discourse-cdn.com/v4/letter/j/e47774/32.png) [@Josh\_Guild](https://community.zeek.org/u/Josh_Guild)\
**Post date:** [April 14, 2016, 8:18pm UTC](https://community.zeek.org/t/weird-log-help/4110/1 "2016-04-14T20:18:22Z")

</div>

Howdy all,

I’m trying to debug some traffic that is coming off an aggregator right now. I was pointed to this helpful set of slides from Vlad on how to troubleshoot and verify a network ([https://speakerdeck.com/vladg/bro-deployment-verification-and-troubleshooting](https://speakerdeck.com/vladg/bro-deployment-verification-and-troubleshooting)).

Looking at the weird.log from a ~2 min pcap on a network with ~6 Gbps throughput, I’ve noticed these entries in the weird.log (top 10 or so).

5454 line\_terminated\_with\_single\_CR  
4012 above\_hole\_data\_without\_any\_acks  
2827 TCP\_ack\_underflow\_or\_misorder  
2601 SYN\_seq\_jump  
2395 TCP\_seq\_underflow\_or\_misorder  
2192 FIN\_advanced\_last\_seq  
1330 HTTP\_version\_mismatch  
570 bad\_HTTP\_request  
333 unescaped\_special\_URI\_char  
205 window\_recision  
151 dns\_unmatched\_msg

Now my questions are these - 1) That seems like a lot of errors for a small sample set but I don’t have a reference point for a network of this size. Does anyone else have an equivalent network that they could sanity check for me? 2) Is there a good reference for these weird.log entries that I can look at to try to pin down what is going wrong in the network? I’m particularly interested in the HTTP\_version\_mismatch and a few other that Vlad mentioned in his presentation.

The main reason I’m interested in the details on HTTP\_version\_mismatch is because I have two pcaps from two separate ports off the aggregator and, for some reason, one is showing as HTTP2 (but only in the OSX version of Wireshark) and Bro can’t read pcap properly. The other pcap is read just fine.

Sorry for the wall of text but if anyone can point me in the right direction, I’d be much obliged. Thanks!

---

<div class="post-metadata">

**Author:** ![Daniel\_Guerra](https://avatars.discourse-cdn.com/v4/letter/d/b5ac83/32.png) [@Daniel\_Guerra](https://community.zeek.org/u/Daniel_Guerra)\
**Post date:** [April 14, 2016, 10:07pm UTC](https://community.zeek.org/t/weird-log-help/4110/2 "2016-04-14T22:07:17Z")

</div>

I don’t know your situation but this looks like reordering problem. All tools expect a time order.

Timeout increase might help.

---

<div class="post-metadata">

**Author:** ![Josh\_Guild](https://avatars.discourse-cdn.com/v4/letter/j/e47774/32.png) [@Josh\_Guild](https://community.zeek.org/u/Josh_Guild)\
**Post date:** [April 15, 2016, 12:35pm UTC](https://community.zeek.org/t/weird-log-help/4110/3 "2016-04-15T12:35:19Z")

</div>

Thanks, Dan, I’ll look into this.  
When I analyze the pcap in Wireshark I see a lot of “port reuse” errors as well which I think it indicative of this as well.

---

<div class="post-metadata">

**Author:** ![Daniel\_Guerra](https://avatars.discourse-cdn.com/v4/letter/d/b5ac83/32.png) [@Daniel\_Guerra](https://community.zeek.org/u/Daniel_Guerra)\
**Post date:** [April 15, 2016, 10:43pm UTC](https://community.zeek.org/t/weird-log-help/4110/4 "2016-04-15T22:43:33Z")

</div>

Use reorderpcap

[https://www.wireshark.org/docs/man-pages/reordercap.html](https://www.wireshark.org/docs/man-pages/reordercap.html)

Or it might help to install the tcprs plugin.

You could could some timeout tweaking too.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:43pm UTC](https://community.zeek.org/t/weird-log-help/4110/5 "2022-05-06T15:43:36Z")

</div>


