A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for further processing!
Want to see multiple Zeek logs for the same connection ID (uid)or file ID (fuid)? Here are the hits from files.log, http.log, andconn.log for a single uid:
You can perform subnet searching on Zeek's…