Zeek Newsletter - Issue 58 - December 2025

Happy New Year and welcome to the Zeek Newsletter.

In this Issue:

TL;DR: Zeek 8.1 RC2 is out and community testing is encouraged before the official release. Registration for our workshop at CERN is still open, Zeek training is coming to the NSF regional summit in April, and we published new scripting content!


Community News & Reminders


:light_bulb: Zeek Tip of the Month

You can compute the community ID for a connection on the command-line using -e directly.

$ zeek -e 'print community_id_v1([$orig_h=127.0.0.1, $orig_p=1234/udp, $resp_h=8.8.4.4, $resp_p=53/udp])'

1:akEF2NwEkbyNtzk1SdCogtbMei4=

Share your tricks, shortcuts, or techniques with us using this form.


Community Call Recap

Highlights from this month’s call:

  • Zeek 8.1 RC2 available: The team released the second release candidate and is encouraging community testing before the official release featuring ZeroMQ as the default backend.

  • Training expansion: We’re hoping to add more Zeek trainings to the calendar in 2026 as NSF is exploring regional semi-annual workshops in addition to their annual summit.

  • Real-world integration stories: Community members Kevin and Tom shared their Zeek deployments, including Security Onion + Elastic + Azure Sentinel for threat hunting, and a university’s multi-continent custom pipeline with AI-powered analysis.

Missed it? Watch the recording on our YouTube Channel.

:date: The next call is February 4 at 10am Pacific Time. Use this Zoom link to join. There’s no registration required, just drop in and join the conversation. See you there!


Development Updates

Zeek 8.1 is in its final testing phase with Release Candidate 2 (RC2) now available. The team is actively seeking community feedback on this major release, which introduces ZeroMQ as the default cluster backend for the first time. Users deploying clusters via ZeekControl will now run on ZeroMQ by default, representing a significant architectural shift for the project.

The development team is particularly encouraging members of the Testing Group to try out RC2 and report any unexpected behavior, performance differences, or issues. If testing goes smoothly, the team plans to release Zeek 8.1 shortly thereafter. This represents a major milestone that the team has been working toward throughout the fall and winter months.

As always, follow development progress on GitHub to stay current with the latest changes.


Ecosystem News


Zeek Packages

Anyone in the community can write add-on functionality for Zeek via packages.

Recently added or updated packages are always visible on GitHub directly, via the following search of pull requests to our package repository:

https://github.com/zeek/packages/pulls?q=is%3Apr+is%3Aclosed

Recent Packages:


Get Involved

Thanks for being part of the community. We’ll see you next time!