Skip to main content
Splunk Lantern is currently being updated. If you notice anything unusual, it should resolve soon, but you can always report issues on our Community Slack. Thank you for your patience.

 

Splunk Lantern

Zeek

 

Zeek sits on a hardware, software, virtual, or cloud platform that observes network traffic. Zeek interprets what it sees and creates compact, high-fidelity transaction logs, file content, and fully customized output. Software administrators use Zeek data in a Splunk deployment to analyze packet capture data directly or use it as a contextual data feed to correlate with other vulnerability related data in the Splunk platform. In the Common Information Model, Zeek data can be mapped to multiple data models, such as Certificates or Network Resolution, depending on the field.

Before looking at documentation for specific data sources, review the Splunk Docs information on general data ingestion: