Skip to main content
Warning
This app is archived. App archiving documentation
Splunk Add-on for Zeek aka Bro app icon

Splunk Add-on for Zeek aka Bro

**The Splunk Add-on for Zeek aka Bro is being replaced by a the TA For Zeek (https://splunkbase.splunk.com/app/5466/)**Built by Splunk Works
splunk product badge

Default Version 4.0.0

December 11, 2018

Compatibility

Splunk Enterprise

Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 4.x

Rating
5
(8)

Log in to rate this app

Support
Archived Add-on
Ranking

#33 in Utilities

**The Splunk Add-on for Zeek aka Bro is being replaced by a the TA For Zeek (https://splunkbase.splunk.com/app/5466/)** The Splunk Add-on for Zeek aka Bro allows a Splunk software administrator to analyze packet capture data directly or use it as a contextual data feed to correlate with other vulnerability related data in the Splunk plaftorm. This add-on provides the inputs and CIM-compatible knowledge to use with other Splunk apps, such as Splunk Enterprise Security and the Splunk App for PCI Compliance.