by Johanna Amann | Apr 29, 2026 | How-to, logging
Zeek can write the same log stream in multiple formats simultaneously. If you need JSON for your SIEM and TSV for long-term archives, you’re in luck: a few lines of code handles both. There are several reasons one might want two log formats simultaneously. For...
by Fatema Bannat Wala | Apr 23, 2026 | logging
At ESnet, our Zeek deployment was logging 4.2 million weirds per day. When we investigated, 90% were DNS-related and 98% of those came from a single opcode. After submitting a PR to fix it, daily weirds dropped to 1.3 million. Here’s how we tracked it down. What...
by Robin Sommer | May 25, 2012 | 2.1, development, logging, preview
Bro’s default ASCII log format is not exactly the most efficient way for storing and searching large volumes of data. An an alternative, Bro 2.1 will come with experimental support for DataSeries output, an efficient binary format for recording structured bulk...