Is zeek the best tool to analyze pcaps in my SOC? #10773
-
I am trying to analyze my wireshark pcaps in security onion with kibana and hunt. I have found links and videos. I see some mentions of zeek. I am trying to put this into perspective. Thanks for any help or advice |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments
-
I found this link - https://github.com/Security-Onion-Solutions/securityonion/discussions/5830 |
Beta Was this translation helpful? Give feedback.
-
I found this link - https://github.com/Security-Onion-Solutions/securityonion/discussions/5830 |
Beta Was this translation helpful? Give feedback.
I found this link - https://github.com/Security-Onion-Solutions/securityonion/discussions/5830
and saw this
"If you chose Suricata instead of Zeek for metadata, then there is no reason for Zeek to run. "
Thanks Doug