Bug #16908
openZeek logging issues
100%
Description
A recent change to Zeeks configuration has casued it not to operate properly from the GUI where the logs are not accessible.
The problem is with the Zeek NSM -> Real-Time Inspection facility where I am presented with an empty list but the directories are populated with data.
Zeek looks like it's functioning properly at the OS level but the interpretation of the directory locations from the GUI are not being picked up correctly.
I've tried adjusting the ZeekControl Config -> Log Store Directory option but the issue was not resolved.
LOG ENTRIES
-----------
NOTICE The command '/usr/local/etc/rc.d/zeek.sh stop' returned exit code '1', the output was 'Error: zeekctl option "spooldir" directory not found: /usr/local/spool'
NOTICE The command '/usr/local/etc/rc.d/zeek.sh restart' returned exit code '1', the output was 'Error: zeekctl option "spooldir" directory not found: /usr/local/spool mount: /proc: No such file or directory Error: zeekctl option "spooldir" directory not found: /usr/local/spool'
REFERENCES:
https://forum.netgate.com/topic/174221/zeek-installed-but-nothing-in-logs
HARDWARE -> XG7100U / SG1100
PFSENSE -> 26.03
ZEEK VER -> 3.0.4
ZEEK PKG -> 8.0.5
Updated by Kris Phillips 2 months ago
- Status changed from New to Confirmed
I can confirm this behavior for the package. Seems the default directory doesn't exist and doesn't get created automatically.
Marking Confirmed.
Updated by Jim Pingle 26 days ago
- Subject changed from ZEEK -> GUI Logging issues to ZEEK Logging issues
- Status changed from Confirmed to In Progress
- Assignee set to Jim Pingle
There are many more related issues here where it isn't handling the log configuration or data correctly.
Updated by Jim Pingle 26 days ago
- Subject changed from ZEEK Logging issues to Zeek logging issues
- Status changed from In Progress to Feedback
- % Done changed from 0 to 100
Fixed in the latest version of the package.
Also available in: Atom