Skip to content

Add IANA service name and description enrichment to Zeek's known_services.log #705

Description

@IdahoManny

Adds support for parsing a custom Zeek log (iana_service.log) adding fields to zeek's known_services.log that enriches connections with IANA service names and categories descriptions based on protocol and destination port.

Includes:

  • IANA_Enrichment.zeek iana_registry.zeek
  • iana_service_map.txt (this is now dynamically generated)
  • 10XX_zeek_iana_service.conf (parsed with known_services.log)

Enables deterministic service attribution using official IANA data.

Image

IANA_Enrichment.zip

Metadata

Metadata

Assignees

Labels

enhancementNew feature or requestzeekRelating to Malcolm's use of Zeek

Fields

No fields configured for Feature.

Projects

Status
Released

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions