BRO-CUT(1) User Commands BRO-CUT(1)

bro-cut - parse bro logs

bro-cut [options] [<columns>]

Extracts the given columns from an ASCII Bro log on standard input. If no columns are given, all are selected. By default, bro-cut does not include format header blocks into the output.

Include the first format header block into the output.
Include all format header blocks into the output.
Convert time values into human-readable format (needs gawk).

-D <fmt> Like -d, but specify format for time (see strftime(3) for syntax).

-F <ofs> Sets a different output field separator.

Print all fields *except* those specified.
Like -d, but print timestamps in UTC instead of local time (needs gawk).

-U <fmt> Like -D, but print timestamps in UTC instead of local time (needs gawk).

For the time conversion, the format string can also be specified by setting an environment variable $BRO_CUT_TIMEFMT

cat conn.log | bro-cut -d ts id.orig_h id.orig_p

bro-cut was written by The Bro Project <info@bro.org>.

This manual page was written by Raúl Benencia <rul@kalgan.cc> for the Debian project (but may be used by others).

November 2014 bro-cut