[Zeek] How to add custom Signatures #4138
Replies: 1 comment
-
Still trying to figure out how to get this to work. Maybe a better question is: |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
I followed the instructions in the docs for adding custom scripts. This does not seem to work for adding custom zeek signatures. It crashes with a parser error when running sudo so-zeek-start.
Here is the doc I followed:
https://docs.securityonion.net/en/2.3/zeek.html
What I have tried
This is the test signature:

This is the init.sls file:

This is the error it is throwing (there is a bunch more of it):

Beta Was this translation helpful? Give feedback.
All reactions