Skip to content
Discussion options

You must be logged in to vote

Here's the relevant documentation:
https://docs.securityonion.net/en/2.4/zeek.html#configuration
https://docs.securityonion.net/en/2.4/administration.html#configuration

Based on the documentation, I would try the following:

  • go to SOC Configuration
  • enable advanced settings
  • navigate to Zeek --> config --> local --> redef
  • apply your Zeek option on the right side
  • click the SYNCHRONIZE GRID button

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@JAEP2
Comment options

Answer selected by dougburks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants