# Starting zeek inside docker container fails when started automatically

**URL:** <https://community.zeek.org/t/starting-zeek-inside-docker-container-fails-when-started-automatically/6884>\
**Category:** Zeek\
**Created:** [January 11, 2023, 5:41pm UTC](https://community.zeek.org/t/starting-zeek-inside-docker-container-fails-when-started-automatically/6884 "2023-01-11T17:41:28Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![0x4A6F686E](https://avatars.discourse-cdn.com/v4/letter/0/b3f665/32.png) [@0x4A6F686E](https://community.zeek.org/u/0x4A6F686E)\
**Post date:** [January 11, 2023, 5:41pm UTC](https://community.zeek.org/t/starting-zeek-inside-docker-container-fails-when-started-automatically/6884/1 "2023-01-11T17:41:28Z")

</div>

Hi all,

I have the latest zeek (5.1.1) inside a docker container. Container was built based on the Dockerfile from the Zeek sources. I have an entrypoint shell script that starts Zeek using: /sbin/runuser -l zeek -c ‘/usr/local/zeek/bin/zeekctl deploy’. This fails as the workers won’t start with the following error: fatal error: problem with interface af\_packet:pcap0 (yes we renamed alll capture interfaces to pcap0, pcap1 to identify them easily and to siimplify the configuration of various applications).

This looks like a permission error, however, when I start the container interactively with bash as entrypoint and I copy/paste the exact command from the entrypoint shell script, everything works just fine.  
BTW: the entrypoint script ends with a ‘sleep infinity’ otherwise the container exits immediately because zeekctl starts everything in the background.

So: if the container is started like this: docker run --rm -it --name zeek --cap-add net\_raw --net=host --entrypoint=/bin/bash , it works;  
if I start it with -d (and not -it) and my default entrypoint script, it won’t work.  
The zeek binary inside the container also had the right capability added.

Anyone any idea?  
Thank you very much in advance.  
Kind regards,

John

---

<div class="post-metadata">

**Author:** ![Christian](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/christian/32/593_2.png) [@Christian](https://community.zeek.org/u/Christian)\
**Post date:** [January 11, 2023, 9:28pm UTC](https://community.zeek.org/t/starting-zeek-inside-docker-container-fails-when-started-automatically/6884/2 "2023-01-11T21:28:23Z")

</div>

Hi John,

Welcome! The “problem with interface” error message should include a reason in parentheses, I presume it actually confirms that it’s a permission problem?

What happens when you use `docker run -it` but give it your entrypoint script as command? Another thing you could try is to examine your environment in both scenarios, to look for clues.

Best,  
Christian

---

<div class="post-metadata">

**Author:** ![awelzel](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/awelzel/32/609_2.png) [@awelzel](https://community.zeek.org/u/awelzel)\
**Post date:** [January 11, 2023, 9:56pm UTC](https://community.zeek.org/t/starting-zeek-inside-docker-container-fails-when-started-automatically/6884/3 "2023-01-11T21:56:41Z")

</div>

> [@0x4A6F686E](#):
>
> This fails as the workers won’t start with the following error: fatal error: problem with interface af\_packet:pcap0 (yes we renamed alll capture interfaces to pcap0, pcap1 to identify them easily and to siimplify the configuration of various applications).

If `af_packet:pcap0` is the string you actually used as interface, try `af_packet::pcap0` with two colons.

The former will use the libpcap packet source and pass `af_packet:pcap0` as interface name (likely erring), while the latter will use the `af_packet` packet source and use `pcap0` as interface name.

---

<div class="post-metadata">

**Author:** ![0x4A6F686E](https://avatars.discourse-cdn.com/v4/letter/0/b3f665/32.png) [@0x4A6F686E](https://community.zeek.org/u/0x4A6F686E)\
**Post date:** [January 13, 2023, 3:37pm UTC](https://community.zeek.org/t/starting-zeek-inside-docker-container-fails-when-started-automatically/6884/4 "2023-01-13T15:37:04Z")

</div>

Hi all,

the single colon instead of the double colon is simply my typo because the zeek-sensor runs in a separate environment and copy/paste is a challenge 🙂

However, I found my mistake: it has to do with the Linux capability cap\_net\_raw that was set on the zeek (and capstats) binary. Somewhere in the docker-entrypoint file there is a chown -R zeek:zeek for the entire zeek-tree in case you give your container seperate user and/or group id’s. After the chown all capabilities are lost, wich is completely understandable from a security point of view.

So thanks for the suggestions. Christian suggestion to simply start my docker-entrypoint interactively pointed me in the right direction.

Have a nice weekend!  
Regards, John

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [April 20, 2026, 9:37pm UTC](https://community.zeek.org/t/starting-zeek-inside-docker-container-fails-when-started-automatically/6884/5 "2026-04-20T21:37:27Z")

</div>

This topic was automatically closed 2 days after the last reply. New replies are no longer allowed.
