# Zeek module not processing logs

**URL:** <https://discuss.elastic.co/t/zeek-module-not-processing-logs/376799>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 4, 2025, 5:43pm UTC](https://discuss.elastic.co/t/zeek-module-not-processing-logs/376799 "2025-04-04T17:43:15Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![thurbs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thurbs/32/142461_2.png) [@thurbs](https://discuss.elastic.co/u/thurbs)\
**Post date:** [April 4, 2025, 5:43pm UTC](https://discuss.elastic.co/t/zeek-module-not-processing-logs/376799/1 "2025-04-04T17:43:15Z")

</div>

Rocky 9 VM. Zeek version 6.0.4

Running into an issue where filebeat isn't processing zeek logs after enabling zeek module. I can get filebeat to process the logs manually through filebeat.yml

I verify through journalctl that filebeat is configuring the intended path of `/var/zeek/logs/current/conn.log`

Here's my zeek.yml

```auto
# Module: zeek
# Docs: https://www.elastic.co/guide/en/beats/filebeat/7.17/filebeat-module-zeek.html

- module: zeek
  connection:
    enabled: true
    var.paths: ["/var/zeek/logs/current/conn.log"]

```

Would love any guidance or help.
