Source

Zeek/Bro

Observe and log network security-related events

Zeek (formerly Bro) is an open-source network security monitoring tool. Zeek creates compact, high-fidelity transaction logs, file content, and output suitable for security and information event management (SIEM) systems.

How to get data flowing

This integration is facilitated through the Cribl Stream Splunk TCP or HEC Source.

  • Configure Zeek to send logs to Splunk.(You can use the Splunk Add-on for Zeek aka Bro.)

  • Configure Stream to listen for Splunk data via Sources > Splunk TCP/HEC.

  • On the Splunk side, configure the system (UF/HF) to send to LogStream.

  • On the Stream side, specify the binding address, listening port, HEC endpoint, event breakers, and optional parameters.

  • Stream will start fetching data as it becomes available.

Cribl, the Data Engine for IT and Security, empowers organizations to transform their data strategy. Customers use Cribl’s suite of products to collect, process, route, and analyze all IT and security data, delivering the flexibility, choice, and control required to adapt to their ever-changing needs.

We offer free training, certifications, and a free tier across our products. Our community Slack features Cribl engineers, partners, and customers who can answer your questions as you get started and continue to build and evolve. We also offer a variety of hands-on-Sandboxes for those interested in how companies globally leverage our products for their data challenges.