Comments (10)
@jazhans do you have
redef LogAscii::use_json=T;
in your local.zeek? That's how I have it setup and is working fine for me.
from docker-zeek.
I had added the following to my local.zeek, that might be my problem
@load policy/tuning/json-logs.zeek
from docker-zeek.
That should have worked. Not sure why it didn't for you, did you load that policy at the start of your local.zeek file or the end? I think order matters within the zeek.local file.
It is doing basically the same thing
https://github.com/zeek/zeek/blob/9d07e4f0b83e23046c11d7120ef1dc3eeb77fd68/scripts/policy/tuning/json-logs.zeek
from docker-zeek.
loaded it at the end of the file and then rebooted the container with no changes in output, i've done the same thing on local installed zeek without any issues...ill try both methods and report back, should have it done by monday.
from docker-zeek.
@nighttardis did you do anything besides add those changes and restart the docker container? I'm still not chaning the output to json even with those tweaks...running on ubuntu18 server host fyi
from docker-zeek.
@jazhans something i just noticed, not sure you did some replacement to make markup happy but you have
sudo docker run -d --cap-add=NET_RAW --net=host -v <pwd>/local.zeek:/usr/local/zeek/share/zeek/site/local.zeek -v <pwd>:/pcap:rw blacktop/zeek -i ens160
are you using the literal string "<pwd>" or are you using "`pwd`" like
sudo docker run -d --cap-add=NET_RAW --net=host -v `pwd`/local.zeek:/usr/local/zeek/share/zeek/site/local.zeek -v `pwd`:/pcap:rw blacktop/zeek -i ens160
The second one would be the proper way to reference `pwd`.
Another thing to try would be to pass the entire path from your local machine you want to mount in the container, instead of using pwd.
from docker-zeek.
@nighttardis i actually just added the pwd to mask my local machine info, maybe a little overkill lol im for sure properly mounting things etc....just keeps turning out the default output, ill keep tinkering
from docker-zeek.
@jazhans no worries I understand, just wanted to make sure there wasn't a simple solution we were both missing.
So I think you're not loading the local zeek config. Try adding "local" to the end of your command.
from docker-zeek.
@nighttardis nailed it homie, that was it lol que the anakin "it's working" gif
from docker-zeek.
Fixed issue, add local to end of command to load in custom local.zeek config -- Ubuntu18 Server
sudo docker run -d --cap-add=NET_RAW --net=host -v `pwd`/local.zeek:/usr/local/zeek/share/zeek/site/local.zeek -v `pwd`:/pcap:rw blacktop/zeek -i ens160 local
from docker-zeek.
Related Issues (20)
- Path for .zeek files described in the documentation is not loaded by Zeek HOT 1
- Extremely helpful!! Need some assistance HOT 3
- Integration question
- add community-id HOT 1
- Docker Compose file with Zeek, Snort, and ELK?
- Error when building zeek:elastic HOT 7
- docker builds for arm HOT 3
- Monitor multi interfaces
- January 11, 2022 Final brownout HOT 2
- suggest for github action
- Forget a newline
- restart: on-failure:5
- Hope to update the package version
- I found that the image didn't seem to work, but it worked when I recompiled it HOT 2
- zeekctl not found
- How to make Zeek container communicate with custom Kafka container
- Zeek container start errors HOT 1
- Do you have plan for zeek 5.0? HOT 1
- Adding Community ID as default HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from docker-zeek.