Closed mmguero closed 3 months ago
zeek-live
container's zeek command line now looks like this:
/opt/zeek/bin/zeek -i af_packet::enp0s25 -U .status -p zeekctl -p zeekctl-live -p local -p worker-1-1 local /opt/zeek/share/zeek/site/extractor.zeek zeekctl base/frameworks/cluster zeekctl/auto
note the af_packet
It would appear that af_packet isn't being enabled for the
zeek-live
container for capture.at first blush the issue is probably either one of two things:
support is not detected although I don't think this is it, as from what I can tell we default to "yes" if we can't explicitly tell that it's "no"