Zeek with elasticsearch

Hi all,

I am running Zeek (Bro) in an offline mode to analyze the pcap file. I get the logs in the "/opt/zeek/logs/current" directory. To further analyze the received logs I am passing those to Filebeat to be visualized further in Kibana. Here where the problem is. I am not getting those logs displayed in Kibana. Zeek module is working fine in the Filebeat. The log file path that appears is /var/log/elasticsearch/gc.log. Any help would be appreciated. Thanks in advance.

Welcome to our community! :smiley:

It's best if you don't create multiple topics on the same question, it makes it harder for people to help you. I'll close this in favour of Analyzing PCAP's with Zeek(Bro) in offline mode.