# simulation network

**URL:** <https://community.zeek.org/t/simulation-network/6217>\
**Category:** Zeek\
**Created:** [August 26, 2020, 12:45pm UTC](https://community.zeek.org/t/simulation-network/6217 "2020-08-26T12:45:11Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ankith\_Kumar\_Hanuman](https://avatars.discourse-cdn.com/v4/letter/a/f04885/32.png) [@Ankith\_Kumar\_Hanuman](https://community.zeek.org/u/Ankith_Kumar_Hanuman)\
**Post date:** [August 26, 2020, 12:45pm UTC](https://community.zeek.org/t/simulation-network/6217/1 "2020-08-26T12:45:11Z")

</div>

Dear All,

Kindly I want to create a simulation environment for Zeek detection capability as IDS and calculate detection time.

The simulation environment will be on citrix xencenter hypervisor. I want to install 2 virtual machines , one of them is zeek IDS and the other one is the attacker machine. I want to send traffic from attacker machine and the traffic is mirrored to Zeek vm to detect attack.

Any help for this setup.

---

<div class="post-metadata">

**Author:** ![Patrick\_Kelley](https://avatars.discourse-cdn.com/v4/letter/p/a87d85/32.png) [@Patrick\_Kelley](https://community.zeek.org/u/Patrick_Kelley)\
**Post date:** [August 26, 2020, 12:54pm UTC](https://community.zeek.org/t/simulation-network/6217/2 "2020-08-26T12:54:07Z")

</div>

Disclaimer: It’s early and I’ve not finished my coffee…

I would create a virtual environment with a dedicated VLAN. In VMware, this can be a virtual network without a physical interface attached. Have Zeek observe traffic of that virtual network. This will keep the traffic observed to just the attack traffic and remove other “noise”.

If you are wishing to test and collect some sort of telemetry, I would get a tcpdump of the attack traffic. You can then replay it all you wish at varying speeds, etc…

I think this is what you are looking for. If not, apologies. I’ll grab another cup of coffee and try harder.

:😄:

---

<div class="post-metadata">

**Author:** ![craig\_bowser](https://avatars.discourse-cdn.com/v4/letter/c/50afbb/32.png) [@craig\_bowser](https://community.zeek.org/u/craig_bowser)\
**Post date:** [August 26, 2020, 12:56pm UTC](https://community.zeek.org/t/simulation-network/6217/3 "2020-08-26T12:56:22Z")

</div>

you also could use something like detectionlab

[https://github.com/clong/DetectionLab](https://github.com/clong/DetectionLab)

---

<div class="post-metadata">

**Author:** ![Ankith\_Kumar\_Hanuman](https://avatars.discourse-cdn.com/v4/letter/a/f04885/32.png) [@Ankith\_Kumar\_Hanuman](https://community.zeek.org/u/Ankith_Kumar_Hanuman)\
**Post date:** [August 26, 2020, 1:38pm UTC](https://community.zeek.org/t/simulation-network/6217/4 "2020-08-26T13:38:25Z")

</div>

First of All, Sorry for interrupting you morning coffee 🙂

I will try to find similar option on citrix xenserver.

Thanks and have a good day.

---

<div class="post-metadata">

**Author:** ![Ankith\_Kumar\_Hanuman](https://avatars.discourse-cdn.com/v4/letter/a/f04885/32.png) [@Ankith\_Kumar\_Hanuman](https://community.zeek.org/u/Ankith_Kumar_Hanuman)\
**Post date:** [August 26, 2020, 3:14pm UTC](https://community.zeek.org/t/simulation-network/6217/5 "2020-08-26T15:14:42Z")

</div>

​Thanks a lot seems great.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:47pm UTC](https://community.zeek.org/t/simulation-network/6217/6 "2022-05-06T15:47:25Z")

</div>


