HEX

Warning: set_time_limit() [function.set-time-limit]: Cannot set time limit - prohibited by configuration in /home/u547966/brikov.ru/www/wp-content/plugins/admin-menu-editor/menu-editor.php on line 745
Server: Apache
System: Linux 4.19.0-0.bpo.9-amd64 x86_64 at red40
User: u547966 (5490)
PHP: 5.3.29-mh2
Disabled: syslog, dl, popen, proc_open, proc_nice, proc_get_status, proc_close, proc_terminate, posix_mkfifo, chown, chgrp, accelerator_reset, opcache_reset, accelerator_get_status, opcache_get_status, pcntl_alarm, pcntl_fork, pcntl_waitpid, pcntl_wait, pcntl_wifexited, pcntl_wifstopped, pcntl_wifsignaled, pcntl_wifcontinued, pcntl_wexitstatus, pcntl_wtermsig, pcntl_wstopsig, pcntl_signal, pcntl_signal_dispatch, pcntl_get_last_error, pcntl_strerror, pcntl_sigprocmask, pcntl_sigwaitinfo, pcntl_sigtimedwait, pcntl_exec, pcntl_getpriority, pcntl_setpriority
Upload Files
File: //usr/share/filebeat/module/zeek/README-developer.md
# Zeek (Bro) module

## Install and Configure Zeek/Bro

### Install Zeek/Bro (for MacOS with Brew)

```
brew install bro
```

* Configure it to process network traffic and generate logs. 
* Edit `/usr/local/etc/node.cfg` to use the proper network interfaces. 
* Edit `/usr/local/etc/networks.cfg` to specify local networks accordingly.
* Set `redef LogAscii::use_json=T;` in `/usr/local/share/bro/site/local.bro` to use JSON output. 

### Install Zeek/Bro (for Ubuntu Linux)

```
apt install bro
apt install broctl
```

* Configure it to process network traffic and generate logs. 
* Edit `/etc/bro/node.cfg` to use the proper network interfaces. 
* Edit `/etc/bro/networks.cfg` to specify local networks accordingly.
* Set `redef LogAscii::use_json=T;` in `/usr/share/bro/site/local.bro` to use JSON output. 

## Start Zeek/Bro

```
sudo broctl deploy
```

## How to try the module from source

Clone and build Filebeat

```
git clone git@github.com:elastic/beats.git
cd beats/x-pack/filebeat
make mage
mage clean update
mage build
```

## Configure Filebeat module and run

Update filebeat.yml to point to Elasticsearch and Kibana. Setup Filebeat.

```
./filebeat setup --modules zeek -e -E 'setup.dashboards.directory=build/kibana'
```

Enable the Filebeat zeek module

```
./filebeat modules enable zeek
```

Start Filebeat

```
./filebeat -e
```

Now, you should see the Zeek logs and dashboards in Kibana.