- Print
- DarkLight
Article summary
Did you find this summary helpful?
Thank you for your feedback
Zeek is a passive, open-source network traffic analyzer. Many operators use Zeek as a network security monitor (NSM) to support suspicious or malicious activity investigations. Zeek also supports a wide range of traffic analysis tasks beyond the security domain, including performance measurement and troubleshooting.
Integration Method: API
Tables: Authentication Activity, Network Activity, DHCP Activity, DNS Activity, FTP Activity, HTTP Activity, Data Security Finding, RDP Activity, SMB Actiivty, Email Actitivity, SSH Activity
Was this article helpful?