Skip to content
  • There are no suggestions because the search field is empty.
PROTECTING OVER $1B IN DAILY TRADES
DEFENDING ENERGY FOR 32+M U.S. USERS
SECURING NETWORKS FOR 52K+ TRANSPORT VEHICLES
DEFENDING $10T+ IN MANAGED ASSETS
SECURING 16+M ANNUAL PATIENT VISITS
Home/Podcasts/Episode 25 - Zeek at 30: Vern...
Episode 25 - Zeek at 30: Vern Paxson on Origins and Enduring Logs (Part 1)
October 8, 2026

Episode 25 - Zeek at 30: Vern Paxson on Origins and Enduring Logs (Part 1)

Episode 25 - Zeek at 30: Vern Paxson on Origins and Enduring Logs (Part 1)
0:00 / 0:00

About the episode

Richard Bejtlich sits down with Vern Paxson, Corelight co-founder and Chief Scientist, to explore Zeek's 30-year journey from a Berkeley Lab research project to a data-rich backbone of modern NDR. They unpack how Zeek evolved from early TCP health measurements into a flexible, scriptable network analysis platform, the value of neutral, long-term logs over real-time alerts, comparisons to intrusion-detection approaches like Snort, and the challenges and opportunities of visibility in enterprise gear. The conversation also touches on the origins of libpcap, tcpdump, and BPF, the role of academia in building enduring tooling, and what this history means for defenders aiming to understand and defend today’s networks.

Episode transcript

Transcript coming soon...