security - How to send zeek logs to a port via tcp or udp? - Stack Overflow

I have zeek installed in centos 9 stream , i want to send the logs generated to a specified port via tc

I have zeek installed in centos 9 stream , i want to send the logs generated to a specified port via tcp or udp as i need this to send logs to a collector configured in a SIEM , is there a zeek script or plugin that enables this ? I only want to use zeek without a 3rd party for forwarding.

I have zeek installed in centos 9 stream , i want to send the logs generated to a specified port via tcp or udp as i need this to send logs to a collector configured in a SIEM , is there a zeek script or plugin that enables this ? I only want to use zeek without a 3rd party for forwarding.

Share Improve this question asked Mar 3 at 16:18 ameliaamelia 391 silver badge4 bronze badges
Add a comment  | 

1 Answer 1

Reset to default 0

It depends on the ingestion format your SIEM expects. You can use Zeek's built-in file logging with something like Filebeat, or add one of the Zeek packages that add additional export formats for Kafka, NATS, ZeroMQ, etc. This might get you started.

I suggest you swing by Zeek's Discourse or Slack, you're likely to get better support there. See here for links.

发布者:admin,转转请注明出处:http://www.yc00.com/questions/1745084018a4610297.html

相关推荐

  • security - How to send zeek logs to a port via tcp or udp? - Stack Overflow

    I have zeek installed in centos 9 stream , i want to send the logs generated to a specified port via tc

    16小时前
    30

发表回复

评论列表(0条)

  • 暂无评论

联系我们

400-800-8888

在线咨询: QQ交谈

邮件:admin@example.com

工作时间:周一至周五,9:30-18:30,节假日休息

关注微信