Replies: 1 comment 1 reply
-
May take some work but logstash has a Kafka input policy you can leverage to consume from Kafka topics https://www.elastic.co/guide/en/logstash/current/plugins-inputs-kafka.html I should also mention Security Onion Pro includes Kafka as a feature and may be an option. https://docs.securityonion.net/en/2.4/pro.html |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hi all,
Is it possible to send Zeek events via Filebeat from a host that is not part of the SecurityOnion grid? My Zeek hosts are FreeBSD based and Elastic Agent is not supported under FreeBSD only beats (filebeat, metricbeat, etc).
Another option I can configure is to use Kafka, but can SecurityOnion act as a consumer for kafka to request Zeek events?
Many thanks.
Beta Was this translation helpful? Give feedback.
All reactions