Skip to content
  • There are no suggestions because the search field is empty.
PROTECTING OVER $1B IN DAILY TRADES
DEFENDING ENERGY FOR 32+M U.S. USERS
SECURING NETWORKS FOR 52K+ TRANSPORT VEHICLES
PROTECTING OVER $10T IN MANAGED ASSETS
SECURING 16+M ANNUAL PATIENT VISITS
Product

Discover Zeek® data

Zeek® transforms traffic into complete, rich, structured metadata and files. Find out what makes it so powerful.

Dicover-Zeek-Data_HeroIllustration

Put everything in context

For decades, the world's best defenders have relied on Zeek network data. Comprised of dozens of logs for varied protocols, plus extracted files, Zeek data is a vital resource for evidence-based defenders as they seek to speed response, amplify hunting, and more, across on-prem, hybrid, and cloud environments. 

Corelight has merged the power of Zeek with a suite of enterprise features that dramatically improve Zeek usability, like an intuitive management UI, sensor health metrics, fleet management, and automated data export to Splunk, Elastic, Kafka, Syslog, and S3. Take Zeek on prem, to the cloud, and beyond with Corelight Sensors.

keyboard-monitoring

Complete, connected, customizable

Fittingly, Zeek’s superpower is connection. As it monitors and records network activity, Zeek assigns a unique connection ID (UID) that links all the logs associated with each connection, while its Community ID connects network flows across data sets, regardless of the tool that produced them.

Zeek is open source and gives you an exceptional amount of control over what you monitor, and where that data goes. You can even write your own parsers, with help from Corelight.  

uid-connects-network

View Zeek data