# Zeek LTS release v9.0.0

**URL:** <https://community.zeek.org/t/zeek-lts-release-v9-0-0/8070>\
**Category:** Announcements\
**Tags:** announcement, releases\
**Created:** [September 14, 2026, 7:33pm UTC](https://community.zeek.org/t/zeek-lts-release-v9-0-0/8070 "2026-09-14T19:33:28Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tim\_Wojtulewicz](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/tim_wojtulewicz/32/594_2.png) [@Tim\_Wojtulewicz](https://community.zeek.org/u/Tim_Wojtulewicz)\
**Post date:** [September 14, 2026, 7:33pm UTC](https://community.zeek.org/t/zeek-lts-release-v9-0-0/8070/1 "2026-09-14T19:33:28Z")

</div>

Zeek 9.0.0 is now available:

> **[Get Zeek – Zeek Network Security Monitor](https://zeek.org/get-zeek/)**
>
> Download Zeek, the open-source network security monitoring tool. Get the source code, Linux binaries, add-on packages, or try Zeek online.

[https://download.zeek.org/zeek-9.0.0.tar.gz](https://download.zeek.org/zeek-9.0.0.tar.gz)

Binary packages will be available [here](https://build.opensuse.org/project/show/security:zeek).

If you missed it, [Christian’s development update post](https://zeek.org/2026/08/zeek-9-0-development-update/) covers what’s new and changing in 9.0.

A few things to check depending on your setup:

- **Broker-based Websocket server removed** The old Broker-based Websocket server has been removed, replaced with a Zeek-native solution. See the NEWS for more information about what this change entails.

- **New UDP packet source** The `zeek-packet-source-udp` plugin is now included by default in Zeek. This packet source can be used to read data directly from VXLAN and GENEVE mirrors directly, useful in cloud environments.

- **Multi-host Systemd generator** The systemd configuration generator added in Zeek 8.1 has been extended to support multiple interfaces as well as support for multi-host deployments.

Compared to Zeek 8.2, this release features two new NTP logs, ntp\_control.log and ntp\_private.log. There are no other structural changes to Zeek’s default log schema. kerberos.log now also reports AP-REQ (Application Request) tickets.

As a reminder, 9.0.0 marks the end of 8.2 support. The 8.0.x LTS line continues getting patch releases as normal until 9.1.0 is released.
