Zeek example – collecting network metadata
Zeek (formerly known as Bro) isn't really an IPS, but it makes a nice adjunct server for your IPS, for your logging platform, as well as for network management. You'll see why that is as we move forward in this section.
First of all, there are a couple of installation options:
- You can install on an existing Linux host (https://docs.zeek.org/en/master/install.html).
- You can install the Security Onion distribution and choose Zeek during the installation (https://download.securityonion.net, https://docs.securityonion.net/en/2.3/installation.html). Security Onion might be attractive because it installs several other components along with Zeek, which might make for a more useful toolset for you.
The Security Onion install, by default, installs Suricata with Zeek, so in a smaller environment, this can make some good sense – also, it's handy to have the information from these two apps on the same...