Hi Everyone,
You might remember our post about the state of the mailing lists in
November 2021 (see
https://lists.zeek.org/archives/list/zeek@lists.zeek.org/thread/VLAAMGVG3NW…),
where we proposed to migrate our mailing lists to Discourse. The
feedback on this has been universally positive.
As a result of this, we are going to migrate all Zeek project mailing
lists to Discourse. We expect this migration process to be finished
around mid-May.
We are going to copy the entire history of all our mailing lists to
Discourse – so there will be no loss of information; all posts will
still be available. For technical reasons, we are not going to migrate
subscription information to discourse. This means that you will have to
sign up to our discourse server once it is available, and manually
enable notifications for posts if you wish to receive them. We will post
an announcement here once the Discourse server is publicly available,
and you can sign up to it. At that time we will also put the mailing
lists into read-only mode.
If you have any questions or concerns about this, either email me
directly, or email the Zeek Leadership team at lt(a)zeek.org.
Johanna Amann (for the Zeek LT)
Hi All
I need assistance with spicy plugin,the btest failed dad with the error
"can't find base/init-bare.zeek" , I did not install zeek because I'm using
corelight platform, but should I install zeek, however I did install
spicy shortly after the corelight installation.
I'm still new in the world of zeeky , I'm ready to create my first plugin
but I realized that my environment and btest is not working with the fresh
download plugin provide with spicy team. Those 3 projects give the same
error: zeek_spicy_openvpn/ zeek-spicy-radius/csv_naive/ those projects
compile fine but btest fails , also I had some issue when I installed the
plugin :
zkg create (failed)
zkg test . ( failed)
cmake install . ( work)
make install . ( work) created .hlto / and copy in corelight modules
btest -->
[ 0%] analyzer.availability ... failed
% 'zeek -NN | grep -qi ANALYZER_SPICY_OpenVPN' failed unexpectedly (exit
code 1)
% cat .stderr
fatal error: can't find base/init-bare.zeek
[ 16%] analyzer.openvpn ... failed
% 'zeek -C -r ${TRACES}/openvpn.pcap
/home/jl/zeek-spicy-openvpn/tests/.tmp/analyzer.openvpn/openvpn.zeek
>openvpn.out' failed unexpectedly (exit code 1)
% cat .stderr
fatal error: can't find base/init-bare.zeek
[ 33%] analyzer.openvpnhmac ... failed
% 'zeek -C -r ${TRACES}/openvpn_udp_tls-auth.pcap
/home/jl/zeek-spicy-openvpn/tests/.tmp/analyzer.openvpnhmac/openvpnhmac.zeek
>openvpn.out' failed unexpectedly (exit code 1)
% cat .stderr
fatal error: can't find base/init-bare.zeek
[ 50%] analyzer.openvpnhmac256 ... failed
% 'zeek -C -r ${TRACES}/openvpn_udp_hmac_256.pcap
/home/jl/zeek-spicy-openvpn/tests/.tmp/analyzer.openvpnhmac256/openvpnhmac256.zeek
>openvpn.out' failed unexpectedly (exit code 1)
% cat .stderr
fatal error: can't find base/init-bare.zeek
[ 66%] analyzer.openvpntcp ... failed
% 'zeek -C -r ${TRACES}/openvpn_tcp_nontlsauth.pcap
/home/jl/zeek-spicy-openvpn/tests/.tmp/analyzer.openvpntcp/openvpntcp.zeek
>openvpn.out' failed unexpectedly (exit code 1)
% cat .stderr
fatal error: can't find base/init-bare.zeek
[ 83%] analyzer.openvpntcphmac ... failed
% 'zeek -C -r ${TRACES}/openvpn-tcp-tls-auth.pcap
/home/jl/zeek-spicy-openvpn/tests/.tmp/analyzer.openvpntcphmac/openvpntcphmac.zeek
>openvpn.out' failed unexpectedly (exit code 1)
% cat .stderr
fatal error: can't find base/init-bare.zeek
Thanks
*JeanLuc*
Software Engineer
MedSec
+1 305 396 6900
JeanlucCouillard(a)medsec.com <YourEmail(a)medsec.com>
--
CONFIDENTIALITY NOTICE: This message (including any attachments) may
contain proprietary, business-confidential, and/or privileged material
intended solely for the addressee(s). If you are not the intended
recipient, you are hereby notified that any use, dissemination,
distribution, or duplication of this communication is strictly prohibited.
If you are not the intended recipient, please contact the sender by reply
email and destroy all copies of the original message.
Hey Zeekers,
I've been running several production instances of Zeek version 3.0.11 with
the Kafka library (version 1.4.2) and the older Metreon Kafka Plugin. No
problems and it is very stable, but it is time to upgrade to LTS and I've
been having serious issues getting a good build of 4.0.5 with a functional
Zeek plugin.
I have tried the newer (supported?) version of the plugin (
https://github.com/SeisoLLC/zeek-kafka), following the instructions (zkg
install seisollc/zeek-kafka --version 1.0.0), and it fails because the
1.0.0 brianch is no longer there. The compile and install works if I leave
the version off or specify --main, but it just never tries to send to
Kafka. I've tried Kafka library version 1.4.2, which is called out in the
docs, and I've even tried the newer stable version 1.6.2.
I even tried using the older Metreon plugin on Zeek 4.0.5, which compiles
but doesn't pass the zeekctl check.
I've tried clean installs from scratch, and upgrades.
Does anyone have Zeek 4.0.5 working with the Kafka plugin? My OS is Ubuntu
18.0.4.
Kurtis Lawson
OK, maybe it's cause it's the end of the week and my brain is fried, but I
can't find the documentation to uninstall zeek.
Basically, I need to remove an old version from one server so I can install
a new version somewhere else...
a link to the documentation would be great....
thanks
zeek version 4.0.1
Craig L Bowser
____________________________
This email is measured by size. Bits and bytes may have settled during
transport.
Hello Everyone,
We are happy to announce that ZeekWeek 2022 will be held on October 11th to
14th in Austin, Texas.
More details, as well as a Call for Presentations will be released in the
next few weeks.
Mark your calendars – and we hope to see you all in Austin in October.
Thank you,
Johanna