Alternatives to Zeek

Network analysis framework that turns traffic into high-level activity logs. The listings below can replace it for an important use case. Each note says what changes if you switch.

The original

Replacements

Listings that take over the same core job as Zeek.

  • Suricata

    Inspect network traffic with an intrusion-detection engine.

    Suricata replaces Zeek's semantic activity logs with a rule-based intrusion-detection engine that supports inline prevention, runs on Linux only, and needs suitable traffic access and maintained rules.

  • Snort

    Open-source intrusion detection and prevention system.

    Snort moves from activity logging to rule-based intrusion detection and inline prevention, adds Windows support, and needs rule tuning, with the newest subscriber rule set being paid.

Similar software

Related functionality, not a direct replacement.