# \#logging

**URL:** https://community.zeek.org/tag/logging/13.md

[Latest](https://community.zeek.org/latest.md) · [Categories](https://community.zeek.org/categories.md) · [Tags](https://community.zeek.org/tags.md)

---

## [Add the zeek\_filename="xxx.log" tag before the JSONL string](https://community.zeek.org/t/add-the-zeek-filename-xxx-log-tag-before-the-jsonl-string/7896)

<div class="topic-metadata">

**Author:** [@alexdinoon](https://community.zeek.org/u/alexdinoon)\
**Replies:** 5\
**Last updated:** [January 2, 2026, 8:14pm UTC](https://community.zeek.org/t/add-the-zeek-filename-xxx-log-tag-before-the-jsonl-string/7896 "2026-01-02T20:14:16Z")

</div>

Hello everyone, I need to send Zeek logs to Cisco SNA. According to the Cisco manual: “Format: The Zeek log generator must add the zeek\_filename="xxx.log" tag before the JSONL string for the Flow Collector.” I need h…

---

## [Delete logs after rotating](https://community.zeek.org/t/delete-logs-after-rotating/7919)

<div class="topic-metadata">

**Author:** [@Artyom\_Kalabukhov](https://community.zeek.org/u/Artyom_Kalabukhov)\
**Replies:** 0\
**Last updated:** [December 16, 2025, 7:54am UTC](https://community.zeek.org/t/delete-logs-after-rotating/7919 "2025-12-16T07:54:33Z")

</div>

I encountered a situation where I needed logs to be written at runtime, but after rotation, the log files should not be saved and archived, but deleted. In the log policy, I found variables for enabling, disabling, and …

---

## [Added Fields Ordering](https://community.zeek.org/t/added-fields-ordering/7778)

<div class="topic-metadata">

**Author:** [@ephemeric](https://community.zeek.org/u/ephemeric)\
**Replies:** 2\
**Last updated:** [May 15, 2025, 6:31pm UTC](https://community.zeek.org/t/added-fields-ordering/7778 "2025-05-15T18:31:14Z")

</div>

Hi, Am I correct in stating that field order is not to be relied on for log parsing? As per #718: Log protocol type for notices - #3 one should/must avoid relying on the order of fields. If I install GitHub - cisagov/…

---

## [How to encode id.orig\_h and id.resp\_h in log or have any way to hide it](https://community.zeek.org/t/how-to-encode-id-orig-h-and-id-resp-h-in-log-or-have-any-way-to-hide-it/7723)

<div class="topic-metadata">

**Author:** [@trong](https://community.zeek.org/u/trong)\
**Replies:** 6\
**Last updated:** [March 14, 2025, 4:40pm UTC](https://community.zeek.org/t/how-to-encode-id-orig-h-and-id-resp-h-in-log-or-have-any-way-to-hide-it/7723 "2025-03-14T16:40:09Z")

</div>

Hi all, I wondering that if id.orig\_h and id.resp\_h can be encoded Thank you everyone for your interest

---

## [Missing http events with zeek](https://community.zeek.org/t/missing-http-events-with-zeek/7669)

<div class="topic-metadata">

**Author:** [@apw](https://community.zeek.org/u/apw)\
**Replies:** 5\
**Last updated:** [December 16, 2024, 4:18pm UTC](https://community.zeek.org/t/missing-http-events-with-zeek/7669 "2024-12-16T16:18:44Z")

</div>

Hello! I’m trying to set up Zeek to get HTTP data from the network interface, but I’m getting fewer HTTP events than I expected. So I recorded a pcap file and tried to feed it to zeek directly and to tshark - and it lo…

---

## [HTTP Body Empty When Analyzing FortiGate SSL-Inspected Mirror Traffic](https://community.zeek.org/t/http-body-empty-when-analyzing-fortigate-ssl-inspected-mirror-traffic/7629)

<div class="topic-metadata">

**Author:** [@kimsw](https://community.zeek.org/u/kimsw)\
**Replies:** 5\
**Last updated:** [November 4, 2024, 2:08pm UTC](https://community.zeek.org/t/http-body-empty-when-analyzing-fortigate-ssl-inspected-mirror-traffic/7629 "2024-11-04T14:08:53Z")

</div>

Hi, I am in the process of configuring a system that FortiGate UTM performs SSL inspection on some HTTPS traffic and sends it to a mirror port, and Zeek receives and analyzes this mirrored traffic. The packet analysis s…

---

## [Zeek event to get connection info when application is detected](https://community.zeek.org/t/zeek-event-to-get-connection-info-when-application-is-detected/7377)

<div class="topic-metadata">

**Author:** [@biswa61](https://community.zeek.org/u/biswa61)\
**Replies:** 7\
**Last updated:** [July 6, 2024, 3:32am UTC](https://community.zeek.org/t/zeek-event-to-get-connection-info-when-application-is-detected/7377 "2024-07-06T03:32:27Z")

</div>

Hi, Is there any event in zeek, which will be fired when any application above Layer 4 ( eg. tcp/udp) is being detected by Zeek? Zeek has support for conn.log, but that will be generated once connection will be removed…

---

## [Issues with my DNS Filter](https://community.zeek.org/t/issues-with-my-dns-filter/7329)

<div class="topic-metadata">

**Author:** [@Greg.N](https://community.zeek.org/u/Greg.N)\
**Replies:** 1\
**Last updated:** [March 27, 2024, 6:53pm UTC](https://community.zeek.org/t/issues-with-my-dns-filter/7329 "2024-03-27T18:53:24Z")

</div>

Hello, I’ve been asked to filter our DNS.log to exclude quite a bit of traffic based on the query. Being quite new to the scripting side of Zeek what I’ve attempted to do doesn’t appear to work with wildcards. In the l…

---

## [Ftp: fuid logged for wrong data-connection](https://community.zeek.org/t/ftp-fuid-logged-for-wrong-data-connection/7276)

<div class="topic-metadata">

**Author:** [@Franky](https://community.zeek.org/u/Franky)\
**Replies:** 3\
**Last updated:** [March 4, 2024, 12:45pm UTC](https://community.zeek.org/t/ftp-fuid-logged-for-wrong-data-connection/7276 "2024-03-04T12:45:11Z")

</div>

Hello, I am a bit confused about the use of the fuid in the ftp.log: my zeek script test.zeek is: redef FTP::logged\_commands += { "LIST", "RETR", "TYPE", "SIZE", "CWD", "DELE" }; event file\_new(f: fa\_file) { …

---

## [How to write rotated logs into YYYY/MM/DD folder hierarchy?](https://community.zeek.org/t/how-to-write-rotated-logs-into-yyyy-mm-dd-folder-hierarchy/7187)

<div class="topic-metadata">

**Author:** [@Greendrake](https://community.zeek.org/u/Greendrake)\
**Replies:** 0\
**Last updated:** [October 26, 2023, 12:27pm UTC](https://community.zeek.org/t/how-to-write-rotated-logs-into-yyyy-mm-dd-folder-hierarchy/7187 "2023-10-26T12:27:44Z")

</div>

How can one configure Zeek to write rotated log files into LogDir/YYYY/MM/DD folder structure instead of the default LogDir/YYYY-MM-DD?

---

## [Redef Log::default\_logdir has bringed an error "redef" used but not previously defined (Log::default\_logdir)""](https://community.zeek.org/t/redef-log-default-logdir-has-bringed-an-error-redef-used-but-not-previously-defined-log-default-logdir/6956)

<div class="topic-metadata">

**Author:** [@jupy](https://community.zeek.org/u/jupy)\
**Replies:** 2\
**Last updated:** [October 16, 2023, 6:37am UTC](https://community.zeek.org/t/redef-log-default-logdir-has-bringed-an-error-redef-used-but-not-previously-defined-log-default-logdir/6956 "2023-10-16T06:37:47Z")

</div>

in local.zeek,add the following statement @load /usr/local/zeek5.0.5-opt/share/zeek/base/frameworks/logging redef Log::default\_logdir = “/root/log”; save,and run “zeek -i ens41f0 /usr/local/zeek/share/zeek/site/local.…

---

## [BlueField-2 NIC 100G live capture not creating intel.log](https://community.zeek.org/t/bluefield-2-nic-100g-live-capture-not-creating-intel-log/7151)

<div class="topic-metadata">

**Author:** [@djordan66](https://community.zeek.org/u/djordan66)\
**Replies:** 9\
**Last updated:** [October 4, 2023, 9:31am UTC](https://community.zeek.org/t/bluefield-2-nic-100g-live-capture-not-creating-intel-log/7151 "2023-10-04T09:31:27Z")

</div>

Hello! I am struggling with Zeek not generating an intel.log file from my 100G interfaces on my cluster. A live capture of a 10G link on the same device, with the same scripts loads, as the 100G interfaces will net an i…

---

## [Try.zeek and local zeek6.0.1 : missing entries](https://community.zeek.org/t/try-zeek-and-local-zeek6-0-1-missing-entries/7145)

<div class="topic-metadata">

**Author:** [@raghunathac](https://community.zeek.org/u/raghunathac)\
**Replies:** 2\
**Last updated:** [September 19, 2023, 6:13am UTC](https://community.zeek.org/t/try-zeek-and-local-zeek6-0-1-missing-entries/7145 "2023-09-19T06:13:08Z")

</div>

I tried a pcapng file on tryZeek online for conn.log parllelly same pacpng, I ran zeek6.0.1 on ubuntu20.04 for conn.log There is a huge mismatch in the total number of packets and udis/flows recorded by tryZeek and loc…

---

## [Cannot catch http.log on internal network machines, but it can be found on external network machines](https://community.zeek.org/t/cannot-catch-http-log-on-internal-network-machines-but-it-can-be-found-on-external-network-machines/7117)

<div class="topic-metadata">

**Author:** [@lideliang](https://community.zeek.org/u/lideliang)\
**Replies:** 6\
**Last updated:** [August 28, 2023, 7:43am UTC](https://community.zeek.org/t/cannot-catch-http-log-on-internal-network-machines-but-it-can-be-found-on-external-network-machines/7117 "2023-08-28T07:43:31Z")

</div>

Hello, I would like to obtain the HTTP request header, request body, response header, and response body through Zeek. Therefore, I built vmware17pro, zeek3.0.1, and metronpro plugin kafka on an external laptop. Everythin…

---

## [Ssl.log fields showing "\*\*" instead of "-" caused by Log::unset\_field redef in local.zeek](https://community.zeek.org/t/ssl-log-fields-showing-instead-of-caused-by-log-unset-field-redef-in-local-zeek/7111)

<div class="topic-metadata">

**Author:** [@Five](https://community.zeek.org/u/Five)\
**Replies:** 2\
**Last updated:** [August 15, 2023, 2:22am UTC](https://community.zeek.org/t/ssl-log-fields-showing-instead-of-caused-by-log-unset-field-redef-in-local-zeek/7111 "2023-08-15T02:22:22Z")

</div>

Hello everyone, I am using zeek 6.0.0. I monitored the interface through a Zeek cluster with 28 lb\_procs by replaying the “all.pcap” file using tcpreplay. Then I find there are “\*\*” in some flows from “ssl.log” as this …

---

## [Zeek stats feature doubt](https://community.zeek.org/t/zeek-stats-feature-doubt/7060)

<div class="topic-metadata">

**Author:** [@biswa](https://community.zeek.org/u/biswa)\
**Replies:** 8\
**Last updated:** [June 29, 2023, 1:50pm UTC](https://community.zeek.org/t/zeek-stats-feature-doubt/7060 "2023-06-29T13:50:04Z")

</div>

Hi, What all kind of stats zeek provides? I can see stats.log, weird-stats.log and many other logs are supported but can’t able to enable these logs. By default my zeek is generating weird, conn and packet filter log. P…

---

## [How to add community ID to conn.log?](https://community.zeek.org/t/how-to-add-community-id-to-conn-log/6877)

<div class="topic-metadata">

**Author:** [@nick](https://community.zeek.org/u/nick)\
**Replies:** 8\
**Last updated:** [January 11, 2023, 9:07pm UTC](https://community.zeek.org/t/how-to-add-community-id-to-conn-log/6877 "2023-01-11T21:07:10Z")

</div>

Hi! Dear Team! I have installed zeek lts 5.0.3 on my machine. I want to add community ID to conn.log, I do that like below: I came acorss errors in picture above, how would I deal with that? Thanks!

---

## [Whitelist content from the weird.log file](https://community.zeek.org/t/whitelist-content-from-the-weird-log-file/6879)

<div class="topic-metadata">

**Author:** [@gnordli](https://community.zeek.org/u/gnordli)\
**Replies:** 7\
**Last updated:** [January 9, 2023, 4:42pm UTC](https://community.zeek.org/t/whitelist-content-from-the-weird-log-file/6879 "2023-01-09T16:42:56Z")

</div>

Hi. I would like to exclude events that is showing up in the weird.log file that is OK. Here is an example of some events. Port 10050 is Zabbix and 3128 is a proxy server where it doesn’t like a connection to a goo…

---

## [Zeek broker and outbound tcp connection](https://community.zeek.org/t/zeek-broker-and-outbound-tcp-connection/6590)

<div class="topic-metadata">

**Author:** [@brijesh](https://community.zeek.org/u/brijesh)\
**Replies:** 2\
**Last updated:** [July 8, 2022, 4:32pm UTC](https://community.zeek.org/t/zeek-broker-and-outbound-tcp-connection/6590 "2022-07-08T16:32:13Z")

</div>

Hello, Excited to learn and use zeek. I was wondering whether there is any way/package/plugin where, I could make outbound tcp connections using broker or scoket library? My goal is to send the logs as they are generat…

---

## [Gathering only DNS Logs](https://community.zeek.org/t/gathering-only-dns-logs/6449)

<div class="topic-metadata">

**Author:** [@Blason\_R](https://community.zeek.org/u/Blason_R)\
**Replies:** 5\
**Last updated:** [February 16, 2022, 2:37pm UTC](https://community.zeek.org/t/gathering-only-dns-logs/6449 "2022-02-16T14:37:51Z")

</div>

Hi Team, I have zeek installed on my DNS server and I need to collect only dns.log. I am struggling to find that configuration where I could stop monitoring all other protocols and wanted to monitor only the dns protoco…
