zeek2es.py - An Application to Make Your Zeek Logs Elastic!
Keith J. Jones, Sr. Security Researcher @ Corelight Labs
1
Feb 11, 2022 - 23:00 UTC | 18:00 EST
Feb 12, 2022 - 00:00 CET
What is Zeek?
2
My Problems
3
My Problems
4
Current Elastic Zeek Support
https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-zeek.html
https://github.com/elastic/beats/tree/master/x-pack/filebeat/module/zeek
5
Filebeat Connection Log
https://github.com/elastic/beats/blob/master/x-pack/filebeat/module/zeek/connection/
There is a lot of field management here for each expected log, which can be error prone and makes updates to schemas difficult (for my research purposes). �
I tried to keep any chance of me introducing errors to a minimum by reading the #field and #types from the Zeek log to build the ES mappings…
6
zeek2es.py Open Source Elastic Support
7
zeek2es.py Open Source Elastic Support
8
Buy today for $0, I’ll also throw in…
9
Buy today for $0, I’ll also throw in…
10
Zeek->ElasticSearch->Kibana Demo
11
12
?
Twitter: https://twitter.com/keithjjones
�LinkedIn: https://www.linkedin.com/in/drkeithjjones/
Slack: https://zeekorg.slack.com appearing as myself
GitHub: https://github.com/keithjjones