Zeek (Bro) Moduleedit

This is a module for Zeek, which used to be called Bro. It parses logs that are in the Zeek JSON format.

Read the quick start to learn how to set up and run modules.

Compatibilityedit

This module has been developed against Zeek 2.6.1, but is expected to work with other versions of Zeek.

Zeek requires a Unix-like platform, and it currently supports Linux, FreeBSD, and Mac OS X. Find out how to use Zeek here: https://www.zeek.org/

Example dashboardedit

This module comes with a sample dashboard. For example:

kibana zeek

Fieldsedit

For a description of each field in the module, see the exported fields section.