Proper method to enable ARP to be collected in local.zeek ? #14021
Unanswered
innovate-support
asked this question in
General
Replies: 1 comment
-
There is no script for arp in |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I'm using SO 2.4.110. I'd like to collect MAC info along with IP and Ports from Zeek. Skynet is suggesting that I simply add
@load base/protocols/arp
to my local.zeek file and restart, supposedly resulting in a arp.log file that's searchable. Is that accurate? I don't want to start messing with zeek files and break my system. If it's that easy, why isn't it collecting arp data by default?Beta Was this translation helpful? Give feedback.
All reactions