Zeek Import Pcap #12276
Zeek Import Pcap
#12276
Replies: 1 comment 4 replies
-
What version of SO are you running? |
Beta Was this translation helpful? Give feedback.
4 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hi, I have one pcap captured in last month . I want that pcap packets to be processed by so-zeek container and generate notice logs on kibana dashboard whenever I will import that pcap.
I have tried tcpreplay and changing timestamp of pcap packets to current timestamp of Security onion But no notice logs were generated.
I have my custom zeek script placed at proper location. Whenever I have imported pcap using so-import-pcap. Able to to notice logs on hunt dashboard for that particular timestamp when that pcap was captured.
But i want the notice logs to be generated on kibana dashboard like logs will generate for live network traffic.
Can someone please help me with that as soon as possible.
Beta Was this translation helpful? Give feedback.
All reactions