September 21, 2026
SuriZeek - Suricata and Zeek Correlation App
Correlates Suricata alerts with the Zeek logs of the same connection. See alert flows, Zeek context and full flow detail in one dashboard.Built by Kaled AljeburSplunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0
Log in to rate this app
SuriZeek links Suricata alerts to the Zeek network logs of the same connection, so an analyst can go from an alert to the surrounding activity in one place. Each Suricata alert is matched to its Zeek events by the connection (both IP addresses and ports, plus protocol), with no extra sensor setup. The Investigation dashboard shows how many alert flows have Zeek context, how many do not, and which Zeek connections have no alert. Click a flow to see every Suricata and Zeek event of that connection in time order: connection state and bytes, DNS query, HTTP request, TLS server name. Also included: Overview, Suricata Alerts and Zeek Context dashboards, click-through between them, and a Search Scope page to set your index, sourcetype and default time range. Requires Suricata eve.json events and Zeek JSON logs (sourcetype zeek_json) in Splunk. Documentation and contact: https://github.com/kaledaljebur/surizeek
Log in to report this app listing.