Comments (10)
seems like you need to add bash
to the apk add --no-cache
line, Alpine by default only ships with /bin/sh
to keep it as small as possible.
from docker-zeek.
please let me know if you get it working, I don't use broctl, but have always wanted to allow for clustered deployments
from docker-zeek.
I got the broctl to run (with bro 2.5). I had to install python inside the container. The logs are being generated and captured, but broctl reports the status as crashed. The same thing happened with another docker bro image based on Alpine. Is it an Alpine issue?
from docker-zeek.
Have you seen it work on a ubuntu based docker image?
from docker-zeek.
Can you give me more info on how you are running it? Are you trying it as a cluster? Or just as a single node?
from docker-zeek.
I am running as a single node. I am running the image as follows:
docker run -d --net=host blacktop/docker-bro -i ens33 -C
docker exec -it /bin/bash
I ran broctl from bash in the container. The status shows as crashed.
The same thing happened with dpisano/docker-bro which is also alpine based. Broctl reports status as crashed, but the logs are being generated and the bro process is running.
However, broctl reports correctly on the image I built based on Ubuntu. But the size of the image I built is unwieldly big. Trying to optimize that size.
from docker-zeek.
Did you ever figure this out?
from docker-zeek.
Also can you try again with this image because I know the Zeek team has been making a LOT of updates to master
from docker-zeek.
I think this is because I compile WITHOUT broctl by default --disable-broctl \
this is to make the default zeek image as small as possible.
from docker-zeek.
I am adding a 🆕 flavor called broctl
that should do what you want.
from docker-zeek.
Related Issues (20)
- Path for .zeek files described in the documentation is not loaded by Zeek HOT 1
- Extremely helpful!! Need some assistance HOT 3
- Json output? HOT 10
- Integration question
- add community-id HOT 1
- Docker Compose file with Zeek, Snort, and ELK?
- Error when building zeek:elastic HOT 7
- docker builds for arm HOT 3
- Monitor multi interfaces
- January 11, 2022 Final brownout HOT 2
- suggest for github action
- Forget a newline
- restart: on-failure:5
- Hope to update the package version
- I found that the image didn't seem to work, but it worked when I recompiled it HOT 2
- zeekctl not found
- How to make Zeek container communicate with custom Kafka container
- Zeek container start errors HOT 1
- Do you have plan for zeek 5.0? HOT 1
- Adding Community ID as default HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from docker-zeek.