Zeek Logs

Connecting Zeek logs to your Panther Console

Overview

Panther supports ingesting Zeek logs via common Data Transport options: Amazon Web Services (AWS) S3 and SQS.

How to onboard Zeek logs to Panther

To pull these logs into Panther:

  1. In the left-hand navigation bar of your Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search for the log type you want to onboard, then click its tile.

  4. Select the data transport method you wish to use for this integration, then follow Panther's instructions for configuring the method:

  5. Configure Zeek to push logs to the Data Transport source.

    • See Zeek's documentation for instructions on pushing logs to your selected Data Transport source.

Supported log types

Zeek.CaptureLoss

Zeek CaptureLoss logs evidence regarding the degree to which the packet capture process suffers from measurement loss.

Reference: Capture Lossarrow-up-right

Zeek.Conn

Reference: conn.logarrow-up-right

Zeek.DHCP

Reference: dhcp.logarrow-up-right

Zeek.DNS

Zeek DNS activity

Reference: Zeek documentation - DNS::infoarrow-up-right

Zeek.DPD

Zeek Dynamic Protocol Detection.

Reference: dpd.logarrow-up-right

Zeek.Files

Reference: files.logarrow-up-right

Zeek.HTTP

Reference: http.logarrow-up-right

Zeek.Notice

Reference: notice.logarrow-up-right

Zeek.NTP

Reference: ntp.logarrow-up-right

Zeek.OCSP

Reference: ocsp.logarrow-up-right

Zeek.Reporter

Zeek internal warnings and errors.

Reference: reporter.logarrow-up-right

Zeek.SIP

This schema represents Zeek SIP analysis logs.

Reference: sip.logarrow-up-right

Zeek.Software

Reference: software.logarrow-up-right

Zeek.SSH

Reference: ssh.logarrow-up-right

Zeek.SSL

Reference: ssl.logarrow-up-right

Zeek.Stats

Reference: stats.logarrow-up-right

Zeek.Tunnel

The purpose of Zeek’s tunnel.log is to identify encapsulated traffic.

Reference: tunnel.logarrow-up-right

Zeek.Weird

Reference: weird.logarrow-up-right

Zeek.X509

Reference: x509.logarrow-up-right

Last updated

Was this helpful?