File: //etc/filebeat/modules.d/zeek.yml.disabled
# Module: zeek
# Docs: https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-module-zeek.html
- module: zeek
capture_loss:
enabled: false
connection:
enabled: false
dce_rpc:
enabled: false
dhcp:
enabled: false
dnp3:
enabled: false
dns:
enabled: false
dpd:
enabled: false
files:
enabled: false
ftp:
enabled: false
http:
enabled: false
intel:
enabled: false
irc:
enabled: false
kerberos:
enabled: false
modbus:
enabled: false
mysql:
enabled: false
notice:
enabled: false
ntp:
enabled: false
ntlm:
enabled: false
ocsp:
enabled: false
pe:
enabled: false
radius:
enabled: false
rdp:
enabled: false
rfb:
enabled: false
signature:
enabled: false
sip:
enabled: false
smb_cmd:
enabled: false
smb_files:
enabled: false
smb_mapping:
enabled: false
smtp:
enabled: false
snmp:
enabled: false
socks:
enabled: false
ssh:
enabled: false
ssl:
enabled: false
stats:
enabled: false
syslog:
enabled: false
traceroute:
enabled: false
tunnel:
enabled: false
weird:
enabled: false
x509:
enabled: false
# Set custom paths for the log files. If left empty,
# Filebeat will choose the paths depending on your OS.
#var.paths: