Skip to main content
SuriZeek - Suricata and Zeek Correlation App app icon

SuriZeek - Suricata and Zeek Correlation App

Correlates Suricata alerts with the Zeek logs of the same connection. See alert flows, Zeek context and full flow detail in one dashboard.Built by Kaled Aljebur
splunk product badge

Default Version 1.5.7

September 21, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

SuriZeek links Suricata alerts to the Zeek network logs of the same connection, so an analyst can go from an alert to the surrounding activity in one place. Each Suricata alert is matched to its Zeek events by the connection (both IP addresses and ports, plus protocol), with no extra sensor setup. The Investigation dashboard shows how many alert flows have Zeek context, how many do not, and which Zeek connections have no alert. Click a flow to see every Suricata and Zeek event of that connection in time order: connection state and bytes, DNS query, HTTP request, TLS server name. Also included: Overview, Suricata Alerts and Zeek Context dashboards, click-through between them, and a Search Scope page to set your index, sourcetype and default time range. Requires Suricata eve.json events and Zeek JSON logs (sourcetype zeek_json) in Splunk. Documentation and contact: https://github.com/kaledaljebur/surizeek