Forward remote Zeek logs to Malcolm for analysis in Dashboards and Arkime #628
-
I need to ingest connection data for a number of clients where I can't otherwise collect it off the wire with Malcolm/Hedgehog. I would like to run Zeek on those clients and send it to Malcolm, this is documented for use in the normal dashboards, however I would like it more tightly integrated with the existing dashboards and most importantly Arkime. I have been trying to trace my way through the hedgehog source/config files to figure out what is different/needed for it to be ingested properly to display like all the other Zeek logs. Does anyone have any pointers or additional info to help make this work? Otherwise I'll keep digging. |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 7 replies
-
Here are some suggestions I'd make:
Let us know how it goes. |
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
Here are some suggestions I'd make:
filebeat/certs/
directory on Malcolm) generated during auth_setup available on the fo…