-
Hi
I looked at the similar issue described here but that solution did not worked out for me. I am using filebeat to ship zeek logs to elasticsearch. In the filebeat container, i can see the zeek logs.
This is my zeek configuration in the docker compose file
Dockerfile
Can anyone point me the cause for the above error ? |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments
-
@Dwijad - it might make sense to share your |
Beta Was this translation helpful? Give feedback.
-
@awelzel You are right ! That was a permission issue. I reconfigured zeek to output logs to |
Beta Was this translation helpful? Give feedback.
@Dwijad - it might make sense to share your
entrypoint.sh
andlocal.zeek
scripts. The one guess is thatVOLUME "/var/log/zeek"
is used for logging and root owned, so you might need to chown that.