Friday, January 29, 2021
Zeek CommunityID - SecurityOnion 16.04
Having recently found out about the Zeek CommunityID, I have been trying to get this implemented in SecurityOnion 16.04. Before anyone even says anything, yes I know that SecurityOnion 2.3 already has the Zeek CommunityID enabled. Lets just say I am currenlty stuck to use 16.04. I can do minor updates/adds to the system. So I am currently on SecurityOnion 16.0.4.7 and figured it would be easy to implement, boy have I been wrong. First things first SO does not have the Zeek Package Manager installed by default, which means I need to try and get the plugin installed with out the package manager also (Plugins are minor, apllications are more of a hassle).
I found a site which walks through the steps on installing the plugin https://dactiv.llc/blog/enable-zeek-community-id/
Of course this states in a normal install of Zeek. Tried to go through the steps, and got stuck on ./configure && make && make install.
The system failed with the error Either 'zeek-config' must be in PATH or '--zeek-dist=' used.
So I went to the Zeek Community, and SecurityOnion community and asked for some help, thier first response was to upgrade SO. Cant, so back to square one.
SecurityOnion folks mentioned to put it in /policy but that did not seem to work.
So talking with Corelight I have been attempting to get this operational, still trying, if anyone has suggestions please let me know. I understand its a restricted playground to get it operational.
No comments:
Post a Comment