x-pack/filebeat/module/zeek/README.md
brew install bro
/usr/local/etc/node.cfg to use the proper network interfaces./usr/local/etc/networks.cfg to specify local networks accordingly.redef LogAscii::use_json=T; in /usr/local/share/bro/site/local.bro to use JSON output.apt install bro
apt install broctl
/etc/bro/node.cfg to use the proper network interfaces./etc/bro/networks.cfg to specify local networks accordingly.redef LogAscii::use_json=T; in /usr/share/bro/site/local.bro to use JSON output.sudo broctl deploy
Grab the filebeat binary from elastic.co, and install it by following the instructions.
Update filebeat.yml to point to Elasticsearch and Kibana. Setup Filebeat.
./filebeat setup --modules zeek -e -E 'setup.dashboards.enabled=true'
Enable the Filebeat zeek module
./filebeat modules enable zeek
Start Filebeat
./filebeat -e
Now, you should see the Zeek logs and dashboards in Kibana.