-
Notifications
You must be signed in to change notification settings - Fork 461
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Additional zeek module log files #3288
Comments
Pinging @elastic/siem (Team:SIEM) |
In elastic#13683, a `signatures` fileset is enabled, but it did not exist. This removes it from the module.d/zeek.yml config file so that the module can start. In elastic#12812 there was a signatures fileset but that PR never merged. Perhaps the fileset from that closed PR can be brought into master. Relates: #18868
The signatures.log fileset was never actually merged into Filebeat. I've opened a PR to fix the default config. We'll have to extract the signatures fileset from the closed PR and bring it into master. elastic/beats#18878 |
In #13683, a `signatures` fileset is enabled, but it did not exist. This removes it from the module.d/zeek.yml config file so that the module can start. In #12812 there was a signatures fileset but that PR never merged. Perhaps the fileset from that closed PR can be brought into master. Relates: #18868
) In elastic#13683, a `signatures` fileset is enabled, but it did not exist. This removes it from the module.d/zeek.yml config file so that the module can start. In elastic#12812 there was a signatures fileset but that PR never merged. Perhaps the fileset from that closed PR can be brought into master. Relates: #18868 (cherry picked from commit 229aee0)
) In elastic#13683, a `signatures` fileset is enabled, but it did not exist. This removes it from the module.d/zeek.yml config file so that the module can start. In elastic#12812 there was a signatures fileset but that PR never merged. Perhaps the fileset from that closed PR can be brought into master. Relates: #18868 (cherry picked from commit 229aee0)
…19041) In #13683, a `signatures` fileset is enabled, but it did not exist. This removes it from the module.d/zeek.yml config file so that the module can start. In #12812 there was a signatures fileset but that PR never merged. Perhaps the fileset from that closed PR can be brought into master. Relates: #18868 (cherry picked from commit 229aee0)
…19042) In #13683, a `signatures` fileset is enabled, but it did not exist. This removes it from the module.d/zeek.yml config file so that the module can start. In #12812 there was a signatures fileset but that PR never merged. Perhaps the fileset from that closed PR can be brought into master. Relates: #18868 (cherry picked from commit 229aee0)
) In elastic#13683, a `signatures` fileset is enabled, but it did not exist. This removes it from the module.d/zeek.yml config file so that the module can start. In elastic#12812 there was a signatures fileset but that PR never merged. Perhaps the fileset from that closed PR can be brought into master. Relates: #18868
|
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
Hi! We're labeling this issue as |
This issue is relevant and should be worked on. The current version of Zeek ( |
Yes @rwaight that would be really neat if we could have some progress here. |
Moved from Beats to Integration repo as enhancements to our Zeek support will be focused on our agent integration. |
👍 Zeek logs are coming up in a new deal with a customer. Still discovering the details on which specific log types must be supported. |
Hi! We just realized that we haven't looked into this issue in a while. We're sorry! We're labeling this issue as |
Describe the enhancement:
I checked again the existing log types that exist in filebeat because of a test I made with zeek 3.0.
https://docs.zeek.org/en/current/script-reference/log-files.html
These issues
elastic/beats#12724
elastic/beats#12812
elastic/beats#14150
elastic/beats#14404
I did now produce a list of all logs to identify all missing log types:
One special part is extra
committedcontributed but not merged but never made it into release somehow unfortunately.At the moment because this one using seek module need you to disable the signatures.log logtype:
https://github.com/elastic/beats/blob/v7.7.0/x-pack/filebeat/modules.d/zeek.yml.disabled#L49-L50
zeek-log-types.xlsx
Additionally documentation doesn't have much information about how to configure seek module:
https://www.elastic.co/guide/en/beats/filebeat/7.7/filebeat-module-zeek.html
The text was updated successfully, but these errors were encountered: