Azure Deployment/Monitoring

I am actively building out an Azure environment and would love to include Zeek in the environment for IDS and monitoring.

Are there any deployment models for how (if possible) this can be achieved? Azure network TAP/SPAN features are wholly subpar for real-life use, but I was hoping some may have solved this without too many complexities.

I deployed it in the past as a basic appliance being in the middle of traffic flows, but this is not ideal for production use.

Any insight/links would be appreciated, my searches so far have not surfaced much.

Thank you.

Ken

Hi Ken — apologies for the slow response. We don’t have much hands-on experience with Azure, but assuming its vTAPs function roughly like AWS’s Traffic Mirroring, check out our blog post on monitoring in the cloud as well as our UDP packet source for directly consuming encapsulated traffic.

If you’re already referring to vTAPs, could you say more regarding how you find them deficient?

Also, I’m curious: are you wondering mostly about traffic capture, or also how to deploy Zeek itself?

Christian,

Thank you for replying. Azure network ‘vTAP’ may be similar but with limitations for vendor lock-in. Within AWS or GCP, what type of system are people using to mirror traffic from? As I understand the design, I would need to mirror/span an interface from a VM which seems limiting for a wider scale network inspection flow process. The best plan I have considered is injecting a couple load balanced, in-line, passive, pass-thru VMs in middle of the ingress/egress flow of my traffic. I’ve done this in the past on a small scale but it does not seem elegant.

Overview page for additional background:

Thank you for your time!

Ken

That is mostly the idea with AWS Traffic Mirroring from what I gather and IIUC it’s the same with Azure vTAP. You create a “traffic mirror session” with the VM as the source and a load-balancer or another VM as the destination (the collector) using the cloud provider’s UI, API or CLI.

Not sure how people do it at scale, but suspect there’s higher-level automation (terraform?) to enable it for all VMs at creation time or some such, or can script it using CLI/API.

All that’s really happening behind the scenes is that the VM’s network traffic packets will be encapsulated with VXLAN or GENEVE and then send out over UDP/IP to the destination/collector.

If you are in control of the OS/distro and it’s on Linux, you can also pull this off by hand via the tc mirred action using an appropriate local vxlan device (there’s examples here and there), or running a small user-space daemon (for example capture-fwd) sniffing on the local interface and mirroring the traffic via UDP to your collector. That doesn’t give you a central point where all traffic flows through, however. It’s more that all traffic is mirrored to a central point directly.

Sorry, time got away from me. Thank you for the additional information. My challenge will be my extensive use of PaaS and private link services that are not traditional VM hosted applications. Maybe in an AKS cluster I might be able to access the underlying node NICs to get traffic forwarded, but, for better or for worse, I’m currently avoiding the complexity of AKS. Terraform or other build templates would definitely need to be in scope for managing at scale, very valid.

I appreciate the insight and will continue to keep this in the back of my mind for the future should my architecture change to allow me to leverage the tremendous insight this tool provides.

Thanks to the community.

Ken