# Which services are identified in conn.log by bro?

**URL:** <https://community.zeek.org/t/which-services-are-identified-in-conn-log-by-bro/5710>\
**Category:** Zeek\
**Created:** [May 28, 2019, 5:07am UTC](https://community.zeek.org/t/which-services-are-identified-in-conn-log-by-bro/5710 "2019-05-28T05:07:00Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sachinji\_Giri](https://avatars.discourse-cdn.com/v4/letter/s/4491bb/32.png) [@Sachinji\_Giri](https://community.zeek.org/u/Sachinji_Giri)\
**Post date:** [May 28, 2019, 5:07am UTC](https://community.zeek.org/t/which-services-are-identified-in-conn-log-by-bro/5710/1 "2019-05-28T05:07:00Z")

</div>

Hi all,

I am looking for the list of services that bro/zeek identifies in conn.log. But I am unable to find out exactly how many services bro identifies. Can someone please point out to me the correct script le or source code or documentation where I can get the list of services that bro detects?

Documentation says :

> application-layer services ( - the service field is filled in as Bro determines a specific protocol to be in use, independent of the connection’s ports)

But where are these services defined? How many are identified in the conn.log?

Thanks in advance!

Regards,

Sachin Giri

---

<div class="post-metadata">

**Author:** ![anthony\_kasza1](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@anthony\_kasza1](https://community.zeek.org/u/anthony_kasza1)\
**Post date:** [May 28, 2019, 3:14pm UTC](https://community.zeek.org/t/which-services-are-identified-in-conn-log-by-bro/5710/2 "2019-05-28T15:14:18Z")

</div>

You can find how this field gets set by grepping through Zeek’s source.

```auto
$ grep -R '\$service' ./scripts | grep 'add'
./scripts/base/frameworks/dpd/main.bro: add c$service[analyzer];
./scripts/base/frameworks/dpd/main.bro: add c$service[fmt("-%s", analyzer)];
./scripts/base/protocols/ftp/main.bro: add c$service["ftp-data"];
./scripts/base/protocols/ftp/gridftp.bro: add c$service["gridftp-data"];
./scripts/base/protocols/ftp/gridftp.bro: add c$service["gridftp"];
./scripts/base/protocols/irc/dcc-send.bro: add c$service["irc-dcc-data"];

```

Most services are identified via the Dynamic Protocol Detection (DPD) framework.  
[https://www.zeek.org/development/howtos/dpd.html](https://www.zeek.org/development/howtos/dpd.html)  
Looking at `scripts/base/frameworks/dpd/main.bro`, you can see that  
the service field is set within the protocol\_confirmation() scriptland  
event which is generated by protocol analyzers in C++land. The  
ProtocolConfirmation() function from `src/analyzer/Analyzer.cc` is how  
the scriptland event is called.

Grepping for that function in the source shows 29 different protocol analyzers.

```auto
$ grep -R 'ProtocolConfirmation' ./src/* | cut -f1 -d':' | grep
'protocol' | cut -d'/' -f5 | sort -u
ayiya
bittorrent
dce-rpc
dhcp
dnp3
dns
ftp
gssapi
gtpv1
http
imap
irc
krb
modbus
mysql
ntlm
pop3
radius
rdp
rfb
sip
smb
smtp
snmp
socks
ssh
ssl
teredo
xmpp

```

It seems that there are, in total, 33 possible connection service values.

-AK

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:46pm UTC](https://community.zeek.org/t/which-services-are-identified-in-conn-log-by-bro/5710/3 "2022-05-06T15:46:31Z")

</div>


