Install Zeek Dependencies
sudo apt-get install cmake make gcc g++ flex bison libpcap-dev libssl-dev python3 python3-dev python3-git python3-semantic-version swig zlib1g-dev libjemalloc-devEnsure all packages are up-to-date
sudo apt-get updatesudo apt-get dist-upgradesudo rebootSetup Separate user for zeek
Create User
sudo groupadd zeeksudo useradd zeek -g zeekSet Password
sudo passwd zeekCreate separate directory
sudo mkdir /opt/zeeksudo chown -R zeek:zeek /opt/zeeksudo chmod 750 /opt/zeekCompile Zeek
Switch to zeek user then download and Compile
cdwget https://download.zeek.org/zeek-5.0.2.tar.gztar -xzvf zeek-5.0.2.tar.gzcd zeek-5.0.2./configure --prefix=/opt/zeek --enable-jemalloc --build-type=releasemakemake installGive Zeek permission to capture packets
sudo setcap cap_net_raw=eip /opt/zeek/bin/zeeksudo setcap cap_net_raw=eip /opt/zeek/bin/capstats