# Zeek/Bro to ECS Field Mappings

**URL:** <https://discuss.elastic.co/t/zeek-bro-to-ecs-field-mappings/324120>\
**Category:** Elasticsearch\
**Tags:** ecs-elastic-common-schema\
**Created:** [January 27, 2023, 3:30pm UTC](https://discuss.elastic.co/t/zeek-bro-to-ecs-field-mappings/324120 "2023-01-27T15:30:34Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![3weekwhiskers](https://avatars.discourse-cdn.com/v4/letter/3/ecd19e/32.png) [@3weekwhiskers](https://discuss.elastic.co/u/3weekwhiskers)\
**Post date:** [January 27, 2023, 3:30pm UTC](https://discuss.elastic.co/t/zeek-bro-to-ecs-field-mappings/324120/1 "2023-01-27T15:30:34Z")

</div>

Is there a Zeek field to ECS field mapping document? Other than the logtype.yml files which actually do the conversion and renames, I have not been able to find anything. I'm avoiding having to build this mapping from scratch because I imagine it must exist by now.

An example is the duration field in Zeek. In the ECS process, it gets turned into temp.duration (according to [connection.yml](https://github.com/legoguy1000/beats/blob/master/x-pack/filebeat/module/zeek/connection/config/connection.yml)) and then into event.duration in the ECS pipeline ([pipeline.yml](https://github.com/legoguy1000/beats/blob/master/x-pack/filebeat/module/zeek/connection/ingest/pipeline.yml))

Thank you!

---

<div class="post-metadata">

**Author:** ![Sunile\_Manjee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunile_manjee/32/111461_2.png) [@Sunile\_Manjee](https://discuss.elastic.co/u/Sunile_Manjee)\
**Post date:** [January 29, 2023, 4:07am UTC](https://discuss.elastic.co/t/zeek-bro-to-ecs-field-mappings/324120/2 "2023-01-29T04:07:40Z")

</div>

Here is the doc on zeek ecs translation. [Zeek | Elastic docs](https://docs.elastic.co/en/integrations/zeek?_gl=1*a9s3yo*_ga*ODY1NDQwMDEzLjE2NzEwMzIwNjc.*_ga_Q7TEQDPTH5*MTY3NDk2MzQ4NS4xMjUuMS4xNjc0OTY1MDYxLjAuMC4w)

If you deploy zeek integration with elastic agent, then you can view/edit the ingest pipeline associated with the zeek integration. that is where the data curated prior to persisting to the corresponding log index.

---

<div class="post-metadata">

**Author:** ![3weekwhiskers](https://avatars.discourse-cdn.com/v4/letter/3/ecd19e/32.png) [@3weekwhiskers](https://discuss.elastic.co/u/3weekwhiskers)\
**Post date:** [January 30, 2023, 12:25pm UTC](https://discuss.elastic.co/t/zeek-bro-to-ecs-field-mappings/324120/3 "2023-01-30T12:25:28Z")

</div>

Thanks - I was more so looking for a one-to-one mapping since this doesn't tell me exactly what Zeek fields map to what ECS fields. Doesn't seem like such document exists though...

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 30, 2023, 12:41pm UTC](https://discuss.elastic.co/t/zeek-bro-to-ecs-field-mappings/324120/4 "2023-01-30T12:41:47Z")

</div>

> [@3weekwhiskers](#):
>
> I was more so looking for a one-to-one mapping since this doesn't tell me exactly what Zeek fields map to what ECS fields.

There isn't a documentation about it, if you are not using the integration what you can do is look how Elastic parse the documents from Zeek to try to map your fields.

You can find the ingest pipelines used here: [https://github.com/elastic/integrations/tree/main/packages/zeek/data\_stream](https://github.com/elastic/integrations/tree/main/packages/zeek/data_stream)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 27, 2023, 12:42pm UTC](https://discuss.elastic.co/t/zeek-bro-to-ecs-field-mappings/324120/5 "2023-02-27T12:42:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
