Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[WIP] [Filebeat] Complete Zeek module #12812

Closed
wants to merge 22 commits into from
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
69 changes: 65 additions & 4 deletions x-pack/filebeat/module/zeek/_meta/config.yml
Original file line number Diff line number Diff line change
@@ -1,17 +1,78 @@
- module: zeek
# All logs
capture_loss:
enabled: true
connection:
enabled: true
dns:
dce_rpc:
enabled: true
http:
dhcp:
enabled: true
dnp3:
enabled: true
dns:
enabled: true
dpd:
enabled: true
files:
enabled: true
ssl:
ftp:
enabled: true
http:
enabled: true
irc:
enabled: true
kerberos:
enabled: true
modbus:
enabled: true
mysql:
enabled: true
notice:
enabled: true
ntlm:
enabled: true
ocsp:
enabled: true
pe:
enabled: true
radius:
enabled: true
rdp:
enabled: true
rfb:
enabled: true
signatures:
enabled: true
sip:
enabled: true
smb_cmd:
enabled: true
smb_files:
enabled: true
smb_mapping:
enabled: true
smtp:
enabled: true
snmp:
enabled: true
socks:
enabled: true
ssh:
enabled: true
ssl:
enabled: true
stats:
enabled: true
syslog:
enabled: true
traceroute:
enabled: true
tunnel:
enabled: true
weird:
enabled: true
x509:
enabled: true

# Set custom paths for the log files. If left empty,
# Filebeat will choose the paths depending on your OS.
Expand Down
Loading