# Zeek Newsletter - Issue 67 - September 2026

**URL:** <https://community.zeek.org/t/zeek-newsletter-issue-67-september-2026/8079>\
**Category:** Announcements\
**Tags:** newsletter\
**Created:** [October 8, 2026, 7:44pm UTC](https://community.zeek.org/t/zeek-newsletter-issue-67-september-2026/8079 "2026-10-08T19:44:35Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![michelle](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/michelle/32/772_2.png) [@michelle](https://community.zeek.org/u/michelle)\
**Post date:** [October 8, 2026, 7:44pm UTC](https://community.zeek.org/t/zeek-newsletter-issue-67-september-2026/8079/1 "2026-10-08T19:44:35Z")

</div>

![image](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/5e9bbc3574d76df6aba1472c0d64e8e094ed6181.jpeg)

# **Welcome to the Zeek Newsletter**

## **In this Issue:**

- [Community News](https://community.zeek.org/t/zeek-newsletter-issue-67-september-2026/8079#p-29903-community-news-reminders-3)
- [Development Updates](https://community.zeek.org/t/zeek-newsletter-issue-67-september-2026/8079#p-29903-development-updates-4)
- [Zeek Techniques](https://community.zeek.org/t/zeek-newsletter-issue-67-september-2026/8079#p-29903-zeek-techniques-5)
- [Packages](https://community.zeek.org/t/zeek-newsletter-issue-67-september-2026/8079#p-29903-packages-6)
- [Get Involved](https://community.zeek.org/t/zeek-newsletter-issue-67-september-2026/8079#p-29903-get-involved-7)

**TL;DR:** Zeek 9.1 development is underway! We also merged an initial DHCPv6 analyzer and are looking for feedback. Plus, Zeek training at NSF Cybersecurity Summit is just around the corner and the Berkeley Workshop recordings are available on YouTube.

* * *

## **Community News & Reminders**

- **Community Call Recap:** This month we covered the start of Zeek 9.1 development. Steve Smoot shared what LLM testing showed about Zeek data and how he uses Spicy to build OT protocol parsers with LLM help.[Watch the recording here](https://youtu.be/h17lrljibTc). The next call is November 4 at 10am PT.[Use this Zoom link](https://us06web.zoom.us/j/99882457331?pwd=WVZLRGtpbmx1V2FqSnlRT1FLRC9lQT09) to join.

- **Zeek Training at the NSF Cybersecurity Summit (Oct. 27):** There’s still time to sign up for Zeek training at [NSF Cybersecurity Summit](https://www.trustedci.org/2026-nsf-cybersecurity-summit)!

- **Discourse Clean Up:** We want to make sure the solutions in our forum are up to date. If you have a few minutes, we’re looking for volunteers to[help review older threads](https://community.zeek.org/t/help-us-update-older-threads/8078/1).

- **Berkeley Workshop Recordings:** Revisit the presentations from Zeek Workshop Berkeley 2026 [on YouTube](https://www.youtube.com/playlist?list=PLc8cHxXjwImA).

- **New Blogs:** Check out Johanna’s “[Reducing Zeek JSON Log Size: Field Name Mapping and Log Filtering Hooks](https://zeek.org/2026/09/reducing-zeek-json-log-size/)” and Christian’s “[Introducing Zeek 9](https://zeek.org/2026/09/introducing-zeek-9/)”.

- **Topic of the Month:** On Monday we wrapped up “The Detections You Rely On”, you can find the [recap from the conversation here](https://zeek.org/2026/10/which-zeek-alerts-do-you-trust/). This month’s topic is “What Do You Do With Your Zeek Data?” [Join the conversation on Slack](http://zeek.org/slack).

* * *

## **Development Updates**

Development on Zeek 9.1, the next feature release, is underway. The team is also spending significant time on security fixes for issues reported through LLM and AI tooling. Patch releases for 8.0 and 9.0 are expected around the end of October.

We’ve merged an [initial version of a DHCPv6 analyzer](https://github.com/zeek/zeek/pull/5712) into Zeek’s master branch. This work was started by first time contributor Van ([VoDongVan](https://github.com/VoDongVan)). Thank you, Van! If you’re using our [zeek/zeek-dev](https://hub.docker.com/r/zeek/zeek-dev) container image, or the [nightly binary packages](https://github.com/zeek/zeek/wiki/Binary-Packages), Zeek should now produce a new dhcpv6.log file.

We’re looking for feedback and iterating on this new analyzer towards the 10.0 release. If you are interested in contributing, have opinions or suggestions about the extensibility and event design of the analyzer and its scripts, or can provide packet captures from complex and interesting DHCPv6 setups, please reach out on [#5947](https://github.com/zeek/zeek/issues/5947) on GitHub.

As always, follow development progress on [GitHub](https://github.com/zeek) to stay current with the latest changes.

* * *

## **💡 Zeek Techniques**

This month’s tip came from Jan, in response to a [question in Slack](https://zeekorg.slack.com/archives/CSZBXF6TH/p1773084830811139) about keeping Zeek from failing to start when a script or package isn’t there.

If you’ve ever uncommented `@load` packages in your local.zeek on a system with no packages installed, you know Zeek won’t start. The `can_load()` function checks whether an `@load` of a given filename, package, or path could succeed by looking for matching scripts in your `ZEEKPATH`. That means you can guard optional loads instead of letting them break startup:

```auto
@if ( can_load("packages") )
@load packages
@endif

```

Keep in mind that `can_load()` only checks that the files exist. It doesn’t parse or validate the script itself, so a package with errors in it will still fail when Zeek loads it.

[Documentation here](https://docs.zeek.org/en/master/scripts/base/utils/packages.zeek.html)

Share your tricks, shortcuts, or techniques with us [using this form](https://forms.gle/1DR2ei98E1n54dg39).

* * *

## **Packages**

Anyone in the community can write add-on functionality for Zeek via packages.

- Browse Zeek packages: [https://packages.zeek.org](https://packages.zeek.org)
- Head to our [zkg package manager documentation](https://docs.zeek.org/projects/package-manager/en/stable/index.html) to get started on your own
- Questions? Check out [#package-sharing](https://zeekorg.slack.com/archives/CTGDGK6EA) to get help

Recently added or updated packages are always visible on GitHub directly, via the following search of pull requests to our package repository:

[https://github.com/zeek/packages/pulls?q=is%3Apr+is%3Aclosed](https://github.com/zeek/packages/pulls?q=is%3Apr+is%3Aclosed)

Recent Updates:

> **[GitHub - sujalavnelavai/zeek-pqc-migration-observatory: Passive TLS cryptographic-migration observability...](https://github.com/sujalavnelavai/zeek-pqc-migration-observatory)**
>
> Passive TLS cryptographic-migration observability for Zeek, including PQC/hybrid capability, negotiated key exchange, classification, migration state, and fallback telemetry.

* * *

## **Get Involved**

- Share ideas or content: [news@zeek.org](mailto:news@zeek.org) or [#security-news](https://zeekorg.slack.com/archives/CT0J1PSR2) on Slack.
- Stay connected: [Discourse](https://community.zeek.org) • [YouTube](https://youtube.com/c/Zeekurity) • [Mastodon](https://infosec.exchange/@zeek) • [Bluesky](https://bsky.app/profile/zeek.org) • [LinkedIn](https://www.linkedin.com/company/zeekurity)
- Check out [Leadership Team meeting notes](https://community.zeek.org/c/lt-meeting-notes/13) for insider updates.
- Looking for Zeek jobs? [See openings on LinkedIn](https://www.linkedin.com/jobs/search/?keywords=zeek).

**Thanks for being part of the community. We’ll see you next time!**
