-
Version2.4.110 Installation MethodSecurity Onion ISO image Descriptioninstallation Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsMeets minimum requirements CPU8 RAM20 Storage for /100 Storage for /nsm300 Network Traffic Collectionspan port Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusYes, there are salt failures (please provide detail below) LogsNo, there are no additional clues DetailReviving this old thread which was unanswered 2y ago and is now locked ========================== Hi all, I am trying to analyze HTTP2 traffic, but it seems the zeek http2 decoder is not installed. it works on my standalone zeek server, but I don't know how to add it to zeek within the security onion environment. Is there a way to install additional zeek packages on top of the default ones that come with security onion? Thanks Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 3 replies
-
There is no current way to add your own plugins. We will look at possibly adding this plugin when we migrate to Zeek 7. There is more to it then just enabling the plugin though. We have to make sure the new log file is picked up and is being parsed properly. Then add it to all the dashboards etc. |
Beta Was this translation helpful? Give feedback.
@masedira With .120 you should see http2 support in Zeek with the mitrecnd/bro-http2 plugin