Skip to content

Can Zeek send an alert if a new device/IP shows up on scans? #572

Closed Answered by mmguero
trwagner1 asked this question in Q&A
Discussion options

You must be logged in to vote

Hi, great question. At the moment we don't have a way to do that, but I've created an issue (#573) to do just that, as it's a great suggestion. In the meantime, there's a few things you can do with visualizations to sort of approximate that:

  • if NetBox inventory autopopulation is turned off then you will see devices that are unknown to the inventory as showing up in the "uninventoried" visualizations on the Asset Interaction Analysis and Zeek Known Summaries dashboard. The idea here being that you run autopopulation for a while, then curate your inventory once it's in a stable state, then observe new ("uninventoried") devices in those visualizations as they are seen.
  • In Arkime, if you go …

Replies: 1 comment 3 replies

Comment options

You must be logged in to vote
3 replies
@trwagner1
Comment options

@mmguero
Comment options

@trwagner1
Comment options

Answer selected by mmguero
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
enhancement New feature or request netbox Related to Malcolm's use of NetBox
2 participants