How to Install Zeek Network Security Monitoring Tool on Ubuntu 22.04

Estimated reading: 3 minutes 679 views

Zeek, formerly known as Bro, is an open-source network security monitoring tool to analyze real-time network traffic. It captures packets and interprets their contents to provide insights into the activities and behaviors occurring on a network.

Zeek Network Security Monitoring offers a powerful and flexible solution for organizations seeking to enhance their network security posture by gaining deeper insights into network traffic and detecting potential threats in real time.

This tutorial will guide you through the installation of the Zeek tool on Ubuntu 22.04.

Step 1 – Install Zeek

The Zeek package is not included in the Ubuntu default repository, so you will need to add Zeek’s official repository to APT.

First, download the Zeek GPG key.

apt update
apt upgrade -y
apt install curl gnupg2 wget -y
Zeek is not in the default Ubuntu repositories, so add the official Zeek repository:
 curl -fsSL https://download.opensuse.org/repositories/security:zeek/xUbuntu_22.04/Release.key | gpg --dearmor | tee /etc/apt/trusted.gpg.d/security_zeek.gpg > /dev/null
echo 'deb http://download.opensuse.org/repositories/security:/zeek/xUbuntu_22.04/ /' | tee /etc/apt/sources.list.d/security:zeek.list

Then, update the repository index and install Zeek using the following command.

apt update -y
apt install zeek -y

During the installation, you will be asked to select your mail server.

Select local only and press the Enter key. You will be asked to provide your mail server hostname.
Once Zeek is installed, add Zeek’s path to the .bashrc file.

echo "export PATH=$PATH:/opt/zeek/bin" >> ~/.bashrc

Reload the .bashrc file using the following command.

source ~/.bashrc

Next, verify the Zeek version using the following command.

zeek --version

Output.

Step 2 – Configure Zeek

Zeek’s default configuration file is located at /opt/zeek/etc/networks.cfg. You can edit it using the Nano editor.

nano /opt/zeek/etc/networks.cfg

Add your internal network as shown below:

64.44.x.0/24 Local Network

Then, edit the Zeek node.cfg configuration file.

nano /opt/zeek/etc/node.cfg

Comment out the following line:

#[zeek]
#type=standalone
#host=localhost
#interface=eth0

Then, add the following configurations.

[zeek-logger]
type=logger
host=your-server-ip
#
[zeek-manager]
type=manager
host=your-server-ip
#
[zeek-proxy]
type=proxy
host=your-server-ip
#
[zeek-worker]
type=worker
host=your-server-ip
interface=eth0

[zeek-worker-lo]
type=worker
host=localhost
interface=lo

Save and close the file, then apply the above configurations using the following command.

zeekctl deploy

You will see the following output.

You can check Zeek’s status using the zeekctl command.

zeekctl status

Output.

Step 3 – Check Zeek Log Files

By default, Zeek stores all log files at /opt/zeek/logs/current/.

To see Zeek log files, run the following command.

ls -l /opt/zeek/logs/current/

Output.

Verify the Zeek cluster log file using the following command.

tail /opt/zeek/logs/current/cluster.log

Output.

To check the Zeek connection status, run the following command.

tail /opt/zeek/logs/current/conn.log

Output.

To stop Zeek, run the following command.

zeekctl stop

Conclusion

Following the step-by-step installation guide outlined in this article, users can deploy Zeek on Ubuntu 22.04 and leverage its capabilities to enhance their network security posture, detect malicious activities, and safeguard critical assets against cyber threats. Try to deploy Zeek on a VPS from Greencloud!

Share this Doc

How to Install Zeek Network Security Monitoring Tool on Ubuntu 22.04

Or copy link

CONTENTS