Hi
I am new at zeek
And I need to achive those points:
how to create a network baseline through zeek, and then compare the live network traffic with the baseline through zeek also to see the alerts that zeek will issue
Is this a school project for comparing intrusion detection systems? Or is this a project for a customer? I’m trying to understand what sort of experience you might have with this kind of project.