# Zkg plugins usage problems

**URL:** <https://community.zeek.org/t/zkg-plugins-usage-problems/7021>\
**Category:** Zeek\
**Created:** [May 6, 2023, 1:24pm UTC](https://community.zeek.org/t/zkg-plugins-usage-problems/7021 "2023-05-06T13:24:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ansk](https://avatars.discourse-cdn.com/v4/letter/a/4af34b/32.png) [@ansk](https://community.zeek.org/u/ansk)\
**Post date:** [May 6, 2023, 1:24pm UTC](https://community.zeek.org/t/zkg-plugins-usage-problems/7021/1 "2023-05-06T13:24:31Z")

</div>

I’m testing Zeek functionality and just faced with Zkg. Following a [Zkg quickstart guide](https://docs.zeek.org/projects/package-manager/en/stable/quickstart.html), preinstalled pip3 with “sudo apt install pip3” , installed “zkg” with “sudo pip3 install zkg” and then tried to get packages “ja3” and “file-extract”. Fun fact, that i wasn’t able to install it or use zkg at any way by the root user

 ![изображение](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/1e2c679bcd6b2e9b453110918cb9fcdad6fcb5f3.png)  
But now i’m not able to use it at all by any user

So, i’m able to run Zeek with local policy by user “eth0” and getting correct result(file-extraction package in loaded and its scripts are loaded)  
But I dont really understand how it is loading, because in local policy file “local.zeek” I dont have any “@load” states for that scripts.  
So I suppose I found place, where zkg stores installed packages, but I dont have it in my “/opt/zeek/share/zeek/site/” directory, as it shown in [Zeek Training day 2022](https://www.youtube.com/watch?v=yBE4TrE6lhY)

So, i’m confused about this:

1. Why I’m not able to run “zkg” and why does this error appear?
2. How package loading process is organised in zeek? Haven’t found required material at zkg documentation

---

<div class="post-metadata">

**Author:** ![ansk](https://avatars.discourse-cdn.com/v4/letter/a/4af34b/32.png) [@ansk](https://community.zeek.org/u/ansk)\
**Post date:** [May 6, 2023, 1:33pm UTC](https://community.zeek.org/t/zkg-plugins-usage-problems/7021/2 "2023-05-06T13:33:45Z")

</div>

Update: I suppose plugin didnt load. I have a different file format generated

 ![изображение](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f3611ccbbb25f5d373185b2872af3f2b146850cf.jpeg)

---

<div class="post-metadata">

**Author:** ![ansk](https://avatars.discourse-cdn.com/v4/letter/a/4af34b/32.png) [@ansk](https://community.zeek.org/u/ansk)\
**Post date:** [May 6, 2023, 1:34pm UTC](https://community.zeek.org/t/zkg-plugins-usage-problems/7021/3 "2023-05-06T13:34:15Z")

</div>

![изображение](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/fdc56672761fbd4e395854eae1c01338d8f4a4a3.png)

---

<div class="post-metadata">

**Author:** ![Christian](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/christian/32/593_2.png) [@Christian](https://community.zeek.org/u/Christian)\
**Post date:** [May 9, 2023, 7:36pm UTC](https://community.zeek.org/t/zkg-plugins-usage-problems/7021/4 "2023-05-09T19:36:28Z")

</div>

Hi there,

Let me try to untangle this a bit. First, `zkg` ships with Zeek by default, so you shouldn’t need to install it. You _can_ install it separately via `pip`, but you then need to ensure that it properly understands your Zeek installation — let’s table that option for the moment.

The thing you install with `zkg` is called a package. A plugin is binary code — a `.so` — that extends Zeek’s core. A package may or may not come with a plugin. The packages you’ve mentioned do not involve plugins.

`zkg` distinguishes between installing a package and loading it (i.e., making it active in Zeek). By default, installation of a package leads to it being loaded. The tail end of local.zeek covers the packages:

```auto
# Uncomment this to source zkg's package state
# @load packages

```

Do so, and Zeek will use the installed packages.

You can alternatively also load select packages only by saying `@load ja3` or whatever is the name of that package. You’ll see that `zkg` places symlinks into your installation’s `site` folder for that purpose.

Your screenshots show that packages are active.

Hope this helps,  
Christian
