Security-Onion-Solutions / security-onion

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management
https://securityonion.net
3.06k stars 517 forks source link

Zeek 3.0.13 #1821

Closed dougburks closed 3 years ago

dougburks commented 3 years ago

https://lists.zeek.org/archives/list/zeek-announce@lists.zeek.org/thread/UIOWWQZDXP2HPH4EKHYS4UGFQVBS2H2N/

dougburks commented 3 years ago

List of packages to be tested:

An overview of the testing process can be found in the comments below.

Please record all testing results via comments on this issue.

Thanks in advance for your time and effort!

dougburks commented 3 years ago

How To Start Testing

dougburks commented 3 years ago

How To Verify Proper Zeek Operation

Please test in as many different combinations as possible:

cm-ops commented 3 years ago

Testing guidelines were verified and all symlinks, settings, files, and logs were validated on all tests.

Evaluation Mode: no Issues Production Mode: (Standalone and Distributed) no issues

Single sniffing interface: no issues Multiple sniffing interfaces: no issues

File extraction enabled or disabled: no issues json-logs enabled or disabled: no issues

New installation: no issues Upgrade: no issues

Zeek cluster mode - PF_RING (lb_method=pf_ring) vs AF_PACKET (lb_method=custom): no issues

dougburks commented 3 years ago

Thanks @cm-ops !

dougburks commented 3 years ago

Published: https://blog.securityonion.net/2021/02/zeek-3013-now-available-for-security.html