Reputation: 39
I have zeek installed in centos 9 stream , i want to send the logs generated to a specified port via tcp or udp as i need this to send logs to a collector configured in a SIEM , is there a zeek script or plugin that enables this ? I only want to use zeek without a 3rd party for forwarding.
Upvotes: 0
Views: 26
Reputation: 1549
It depends on the ingestion format your SIEM expects. You can use Zeek's built-in file logging with something like Filebeat, or add one of the Zeek packages that add additional export formats for Kafka, NATS, ZeroMQ, etc. This might get you started.
I suggest you swing by Zeek's Discourse or Slack, you're likely to get better support there. See here for links.
Upvotes: 0