# Zeek install monitoring multiple interfaces, need interface in logs

**URL:** <https://community.zeek.org/t/zeek-install-monitoring-multiple-interfaces-need-interface-in-logs/5589>\
**Category:** Zeek\
**Created:** [January 22, 2019, 2:52pm UTC](https://community.zeek.org/t/zeek-install-monitoring-multiple-interfaces-need-interface-in-logs/5589 "2019-01-22T14:52:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Darrell\_Miller](https://avatars.discourse-cdn.com/v4/letter/d/439d5e/32.png) [@Darrell\_Miller](https://community.zeek.org/u/Darrell_Miller)\
**Post date:** [January 22, 2019, 2:52pm UTC](https://community.zeek.org/t/zeek-install-monitoring-multiple-interfaces-need-interface-in-logs/5589/1 "2019-01-22T14:52:55Z")

</div>

Hi,

I’ve been running bro for a few years, a simple straightforward install. I recently have a need for my bro instance to monitor two interfaces (internal network and external network)

I’ve gotten this working, it was straight forward. My issue is in most of the logs there is no tag or field indicating which interface the log entry is referring to. Some logs like weird.log do have a field called “peer”

That indicates what seems to be the interface. DNS.log, and CONN.log do not. Is there an easy way to add this field, or add a field saying which node of the cluster the log entry originated from? I hope that makes sense

Thank you,

Darrell Miller

---

<div class="post-metadata">

**Author:** ![ericooi](https://avatars.discourse-cdn.com/v4/letter/e/ecae2f/32.png) [@ericooi](https://community.zeek.org/u/ericooi)\
**Post date:** [January 22, 2019, 3:56pm UTC](https://community.zeek.org/t/zeek-install-monitoring-multiple-interfaces-need-interface-in-logs/5589/2 "2019-01-22T15:56:05Z")

</div>

Hi Darrell,

This might help – [https://blog.zeek.org/2012/02/filtering-logs-with-bro.html](https://blog.zeek.org/2012/02/filtering-logs-with-bro.html)

Thanks,  
Eric

---

<div class="post-metadata">

**Author:** ![Darrell\_Miller](https://avatars.discourse-cdn.com/v4/letter/d/439d5e/32.png) [@Darrell\_Miller](https://community.zeek.org/u/Darrell_Miller)\
**Post date:** [January 22, 2019, 4:02pm UTC](https://community.zeek.org/t/zeek-install-monitoring-multiple-interfaces-need-interface-in-logs/5589/3 "2019-01-22T16:02:17Z")

</div>

Thanks, I found this right after I hit “send” on my mail.

Here is what I came up with to save anyone else a little bit of time:  
if there is a better way of doing it, please let me know. So far these are the logs I’ve been able to add the interface too. Communications.log did not work using the same pattern.

## —====================================================================================================================

#add interface name to log filename:

event bro\_init()

{

if ( reading\_live\_traffic() )

{

Log::remove\_default\_filter(HTTP::LOG);

Log::add\_filter(HTTP::LOG, [$name = “http-interfaces”,

$path\_func(id: Log::ID, path: string, rec: HTTP::Info) =

{

local peer = get\_event\_peer()$descr;

if ( peer in Cluster::nodes && Cluster::nodes[peer]?$interface )

return cat(“http\_”, Cluster::nodes[peer]$interface);

else

return “http”;

}

]);

Log::remove\_default\_filter(Conn::LOG);

Log::add\_filter(Conn::LOG, [$name = “conn-interfaces”,

$path\_func(id: Log::ID, path: string, rec: Conn::Info) =

{

local peer = get\_event\_peer()$descr;

if ( peer in Cluster::nodes && Cluster::nodes[peer]?$interface )

return cat(“conn\_”, Cluster::nodes[peer]$interface);

else

return “conn”;

}

]);

Log::remove\_default\_filter(Weird::LOG);

Log::add\_filter(Weird::LOG, [$name = “weird-interfaces”,

$path\_func(id: Log::ID, path: string, rec: Weird::Info) =

{

local peer = get\_event\_peer()$descr;

if ( peer in Cluster::nodes && Cluster::nodes[peer]?$interface )

return cat(“weird\_”, Cluster::nodes[peer]$interface);

else

return “weird”;

}

]);

Log::remove\_default\_filter(DNS::LOG);

Log::add\_filter(DNS::LOG, [$name = “DNS-interfaces”,

$path\_func(id: Log::ID, path: string, rec: DNS::Info) =

{

local peer = get\_event\_peer()$descr;

if ( peer in Cluster::nodes && Cluster::nodes[peer]?$interface )

return cat(“DNS\_”, Cluster::nodes[peer]$interface);

else

return “dns”;

}

]);

} #end if

} #end event

## —====================================================================================================================

In your logs folder, each logfile will be split up by the interface:  
DNS\_eth01.log

DNS\_eth02.log  
weird\_eth01.log

weird\_eth02.log

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:46pm UTC](https://community.zeek.org/t/zeek-install-monitoring-multiple-interfaces-need-interface-in-logs/5589/4 "2022-05-06T15:46:18Z")

</div>


