Security-Onion-Solutions / security-onion

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management
https://securityonion.net
3.07k stars 522 forks source link

Zeek 3.0.8 #1779

Closed dougburks closed 4 years ago

dougburks commented 4 years ago

https://github.com/zeek/zeek/releases/tag/v3.0.8

dougburks commented 4 years ago

List of packages to be tested:

An overview of the testing process can be found in the comments below.

Please record all testing results via comments on this issue.

Thanks in advance for your time and effort!

dougburks commented 4 years ago

How To Start Testing

dougburks commented 4 years ago

How To Verify Proper Zeek Operation

Please test in as many different combinations as possible:

cm-ops commented 4 years ago

Testing guidelines were verified and all symlinks, settings, files, and logs were validated on all tests.

• Evaluation Mode (Zeek Standalone mode) vs Production Mode (Zeek cluster mode) o Evaluation : no issues o Production : no issues

• single sniffing interface vs multiple sniffing interfaces o single sniffing interface: no issues o multiple sniffing interfaces: no issues

• file extraction enabled or disabled o enable: no issues o disabled: no issues

• json-logs enabled or disabled o enable: no issues o disabled: no issues

• traffic without vlan tags vs traffic with vlan tags o without: no issues o with: no issues

• new installation vs upgrade o new install: no issues o upgrade: no issues

• Zeek cluster mode - PF_RING (lb_method=pf_ring) vs AF_PACKET (lb_method=custom) o PF_RING: no issues o AF_PACKET: no issues

dougburks commented 4 years ago

Thanks @cm-ops !

dougburks commented 4 years ago

Published: https://blog.securityonion.net/2020/07/zeek-308-now-available-for-security.html