Skip to content

Logstash zeek event failure #678

Closed Answered by mmguero
divinehawk asked this question in Troubleshooting
Discussion options

You must be logged in to vote

There's really only one way around this, and that is to enable JSON mode for your zeek logs:

By telling Hedgehog's Zeek logs to be JSON, Malcolm doesn't have to rely on the field order being consistent.

The corresponding setting in Malcolm, should you desire to set it (although in this case the issue is hedgehog being a different version so it doesn't make much difference) is in ./config/zeek.env

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by divinehawk
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
zeek Relating to Malcolm's use of Zeek logstash Relating to Malcolm's use of Logstash sensor For issues dealing with the Hedgehog OS capture sensor
2 participants
Converted from issue

This discussion was converted from issue #677 on May 16, 2025 21:46.