What is zeek and can I use it to analyze wireshark captures?
What is zeek and can I use it to analyze wireshark captures?
Disclosures: Wireshark pays for my mortgage. My employer makes Packet Analyzer. I'm friends with people at Brim.
Both Wireshark and Zeek use libpcap, which is the de facto standard for raw packet captures, so yes, the same data you'd be feeding to Wireshark to browse, you can also feed to Zeek to analyze.
https://www.csoonline.com/article/3313050/zeek-a-free-powerf...
As to the where - I guess I need to find some port that can give me a mirror of traffic.... But not that easy with heterogeneous lan+cloud+SaaS setup to figure out where/how to source "all" network traffic :/
One key aspect of Zeek is that it can be deployed within a network to passively generate logs. As an incident response consultant, the few times I've worked with a client with Zeek logs, our ability to answer some critical questions in short order was increased dramatically! Back in my Sysadmin days, I used to run Zeek (when it was called Bro) to provide network logs for security review but also for general network analysis.
You can definitely run a pcap capture by wireshark through Zeek. you'd run `zeek -r <yourpcap>` and you'll end up with some lovely TSV separated logs in your current working directory!
Full transparency: I'm not part of the Zeek team, but I did author the original Zeek scripting guide for them back in 2012 or so. For my money, the Zeek team is building some of the better network appliances and detection/logging capabilities available.
It’s more of a Network Security Monitoring tool (NSM) than a Wireshark equivalent
It’s primary use case is to have a server(s) ingesting all traffic in a network and forwarding the traffic metadata to something like an Elastic Stack.
What makes it so powerful though, is that it actually has its own scripting language that allows you create automations based off what type of traffic is observed and these can be super intricate