# Zeek Newsletter - Issue 57 - November 2025

**URL:** <https://community.zeek.org/t/zeek-newsletter-issue-57-november-2025/7912>\
**Category:** Announcements\
**Tags:** newsletter\
**Created:** [December 8, 2025, 9:07pm UTC](https://community.zeek.org/t/zeek-newsletter-issue-57-november-2025/7912 "2025-12-08T21:07:51Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![michelle](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/michelle/32/772_2.png) [@michelle](https://community.zeek.org/u/michelle)\
**Post date:** [December 8, 2025, 9:07pm UTC](https://community.zeek.org/t/zeek-newsletter-issue-57-november-2025/7912/1 "2025-12-08T21:07:51Z")

</div>

![image](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/d359998bd0adcadd9506ca7a29396b8442c2888a.jpeg)

# Welcome to the Zeek Newsletter

In this Issue:

- [Reminders](#p-29576-dont-miss-this-reminders-for-the-community-2)
- [Tip of the Month](#p-29576-zeek-tip-of-the-month-3)
- [Community Call Recap](#p-29576-community-call-recap-4)
- [Development Updates](#p-29576-development-updates-5)
- [Packages](#p-29576-zeek-packages-6)
- [Get Involved](#p-29576-get-involved-8)

TL;DR: Zeek 8.1 enters final stretch with mid-December fork and ZeroMQ as the new default cluster backend, WebSocket bindings demoed for multiple languages, and CERN workshop spots still available!

* * *

## Don’t Miss This – Reminders for the Community

- **Zeek Workshop (Geneva, Mar. 25-26):** Join us for a free, two-day workshop at CERN. [Registration and Call for Presentations can be found on our website.](https://zeek.org/workshop-cern-2026/) Limited spots available.
- **Topic of the Month:** December’s theme is “Zeek & Other Tools”. Join the discussion in [#topic-of-the-month](https://zeekorg.slack.com/archives/C09JEQJAW3G) on Slack and read the [November recap on our blog](https://zeek.org/2025/12/common-mistakes-when-deploying-zeek-and-how-to-avoid-them/).
- **New Blog Post:** [Developing Zeek Scripts with Style](https://zeek.org/2025/12/developing-zeek-scripts-with-style/)

* * *

## 💡 Zeek Tip of the Month

To process compressed pcaps, use `zeek -r -` to read from stdin and `zcat` or `xzcat`.

```auto
$ zcat http.pcap.gz | zeek -r -

$ xzcat http.pcap.xz | zeek -r -

```

Share your tricks, shortcuts, or techniques with us [using this form](https://forms.gle/1DR2ei98E1n54dg39).

* * *

## Community Call Recap

Highlights from this month’s call:

- **Zeek 8.1 development:** Final stretch before mid-December fork. Starting with Zeek 8.1, Zeekctl-managed clusters will use the ZeroMQ cluster backend by default.
- **WebSocket bindings demo:** Benjamin showcased zeek-websocket-rs - a new Rust-based project providing language bindings for Rust, Python, C++, and Node.js simplifying interacting with Zeek’s WebSocket API.

Missed it? Watch the recording on our [YouTube Channel](https://www.youtube.com/watch?v=pP2b9lQAZl8).

📅 The next call is January 7 at 10am Pacific Time. [Use this Zoom link to join.](https://us06web.zoom.us/j/99882457331?pwd=WVZLRGtpbmx1V2FqSnlRT1FLRC9lQT09) There’s no registration required, just drop in and join the conversation. See you there!

* * *

## Development Updates

Zeek 8.1 is entering its final stretch, with plans to fork mid-December 2025. The team aims to release it before the holidays as a “developer release” to allow community testing over the break, with finalization coming in the new year. This is a significant release featuring the highly anticipated [switch to ZeroMQ as the default messaging backend](https://community.zeek.org/t/switching-to-zeromq-by-default/7911)—a major architectural change for the project. While the team expects some users may encounter unexpected behavior, easy rollback options to Broker will be available for those who prefer to wait.

The large Zeek Package Manager (zkg) update originally planned for 8.1 has been moved to the 8.2 cycle to allow more development time. However, other experimental work is progressing, including new WebSocket bindings to replace broker-based ones and a prototypical XDP shunter.

Homebrew now installs Node’s shared library. This makes it possible to build Zeek’s Javascript support on macOS. We have identified and fixed a couple issues specific to how Node runs on macOS, and are in the process of backporting them to the LTS release branch. Javascript support is enabled automatically if Node is detected, and can be disabled by configuring with `--disable-javascript`.

[Version 8.0.4](https://community.zeek.org/t/zeek-bugfix-release-8-0-4/7894) remains available for users on the 8.0 release train, containing bug fixes with no critical issues. The team expects to share 8.1 release candidate updates at January’s Community Call, with the full release anticipated by February’s call.

As always, follow development progress on [GitHub](https://github.com/zeek) to stay current with the latest changes.

* * *

## Zeek Packages

Anyone in the community can write add-on functionality for Zeek via packages.

- Browse Zeek packages: [https://packages.zeek.org](https://packages.zeek.org)
- Head to our [zkg package manager documentation](https://docs.zeek.org/projects/package-manager/en/stable/index.html) to get started on your own
- Questions? Check out [#package-sharing](https://zeekorg.slack.com/archives/CTGDGK6EA) to get help

Recently added or updated packages are always visible on GitHub directly, via the following search of pull requests to our package repository:

[https://github.com/zeek/packages/pulls?q=is%3Apr+is%3Aclosed](https://github.com/zeek/packages/pulls?q=is%3Apr+is%3Aclosed)

### Recent Packages:

> **[GitHub - awelzel/zeekjs-udp-logging: A proof-of-concept JavaScript-based UDP logger for...](https://github.com/awelzel/zeekjs-udp-logging)**
>
> A proof-of-concept JavaScript-based UDP logger for Zeek

> **[GitHub - corelight/zeek-mercury-npf](https://github.com/corelight/zeek-mercury-npf)**
>
> Contribute to corelight/zeek-mercury-npf development by creating an account on GitHub.

* * *

## Get Involved

- Share ideas or content: [news@zeek.org](mailto:news@zeek.org) or [#security-news](https://zeekorg.slack.com/archives/CT0J1PSR2) on Slack.
- Stay connected: [Discourse](https://community.zeek.org) • [YouTube](https://youtube.com/c/Zeekurity) • [Mastodon](https://infosec.exchange/@zeek) • [Bluesky](https://bsky.app/profile/zeek.org) • [LinkedIn](https://www.linkedin.com/company/zeekurity)
- Check out [Leadership Team meeting notes](https://community.zeek.org/c/lt-meeting-notes/13) for insider updates.
- Looking for Zeek jobs? [See openings on LinkedIn](https://www.linkedin.com/jobs/search/?keywords=zeek).

Thanks for being part of the community. We’ll see you next time!

---

<div class="post-metadata">

**Author:** ![michelle](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/michelle/32/772_2.png) [@michelle](https://community.zeek.org/u/michelle)\
**Post date:** [December 15, 2025, 6:45pm UTC](https://community.zeek.org/t/zeek-newsletter-issue-57-november-2025/7912/2 "2025-12-15T18:45:03Z")

</div>


