IMPORTANT: No additional bug fixes or documentation updates
will be released for this version. For the latest information, see the
current release documentation.
Zeek (Bro) Module
editZeek (Bro) Module
editThis is a module for Zeek, which used to be called Bro. It parses logs that are in the Zeek JSON format.
The Zeek SSL fileset will handle fields from these scripts if they are installed in Zeek.
Read the quick start to learn how to configure and run modules.
Compatibility
editThis module has been developed against Zeek 2.6.1, but is expected to work with newer versions of Zeek.
Zeek requires a Unix-like platform, and it currently supports Linux, FreeBSD, and Mac OS X.
Example dashboard
editThis module comes with a sample dashboard. For example:
Fields
editFor a description of each field in the module, see the exported fields section.