View a markdown version of this page

Zeek integration configuration - Amazon CloudWatch
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Zeek integration configuration

Zeek is an open-source network security monitoring platform widely used for analyzing network traffic and generating detailed logs about network activities across an organization's infrastructure. It passively monitors network traffic and provides deep visibility into communications by producing structured logs for multiple network protocols and security-relevant events. CloudWatch pipelines allow ingestion of Zeek log data into CloudWatch Logs, providing scalable collection, processing, normalization, and integration with downstream Amazon security and monitoring services.