Zeek (formerly Bro) is an open-source network security monitoring tool. Zeek creates compact, high-fidelity transaction logs, file content, and output suitable for security and information event management (SIEM) systems.
How to get data flowing
This integration is facilitated through the Cribl Stream Splunk TCP or HEC Source.
Configure Zeek to send logs to Splunk.(You can use the Splunk Add-on for Zeek aka Bro.)
Configure Stream to listen for Splunk data via Sources > Splunk TCP/HEC.
On the Splunk side, configure the system (UF/HF) to send to LogStream.
On the Stream side, specify the binding address, listening port, HEC endpoint, event breakers, and optional parameters.
Stream will start fetching data as it becomes available.