Which have your challenges been with Zeek so far?

Hello Zeek Community,

I’m looking for insights on improving Zeek IDS management. Could you please share your thoughts on the following:

  1. What challenges do you face with Zeek IDS management (initial setup, maintenance etc)?
  2. How do you handle configuration and monitoring (third party tools, UI)?
  3. What features or tools would make your work easier?

Thank you for your input!

Best,
Chris

I am new to Zeek and have stuggled immensely with zkg packages and outdated failing tests.

I know I’m not the smartest person around but Zeek has some of the most arcane subsystems I have ever encountered.