Connections To Destination Ports Above 1024 The dashboards here give a nice overview of some of the data collected from our network. Zeek Configuration. In this (lengthy) tutorial we will install and configure Suricata, Zeek, the ELK stack, and some optional tools on an Ubuntu 20.10 (Groovy Gorilla) server along with the Elasticsearch Logstash Kibana (ELK) stack. The Filebeat Zeek module assumes the Zeek logs are in JSON. To build a Logstash pipeline, create a config file to specify which plugins you want to use and the settings for each plugin. Installing Elastic is fairly straightforward, firstly add the PGP key used to sign the Elastic packages. Automatic field detection is only possible with input plugins in Logstash or Beats. There is a new version of this tutorial available for Ubuntu 22.04 (Jammy Jellyfish).