MODES

VERSION CHECK

#check zeek version
root@dco:~$ zeek -v
 * the -v is for version information.

ZEEK: SERVICE MODE

this mode enables zeek to listen on live network traffic. the created logs will be located in the default log path /opt/zeek/logs

#run zeek as a service
root@dco:~$ sudo su
 * "ZeekControl" module requires superuser permissions to use
    - ZeekControl is a module.
root@dco:~$ zeekctl
 Welcome to ZeekControl 2.X.0

[ZeekControl] > status
 Name         Type       Host          Status    Pid    Started
 zeek         standalone localhost     stopped

[ZeekControl] > start
 starting zeek ...

[ZeekControl] > status
 Name         Type       Host          Status    Pid    Started
 zeek         standalone localhost     running   2541   13 Mar 18:25:08

[ZeekControl] > stop
 stopping zeek ...

[ZeekControl] > status
 Name         Type       Host          Status    Pid    Started
 zeek         standalone localhost     stopped

ZEEK: PCAP MODE

this mode sets Zeek to read pcap files. once the pcaps are processed, Zeek automatically creates log files according to the traffic and the created logs will be stored in the working directory

Last updated