-
Notifications
You must be signed in to change notification settings - Fork 151
Open
Description
After installing JA4 into zeek on Ubuntu 24.04 using sudo zkg install zeek/foxio/ja4, I don't see any fields in the zeek logs that look like JA4. The installation appears to be OK:
$ sudo zeekctl check
zeek scripts are ok.
$ sudo zkg list
zeek/foxio/ja4 (installed: v0.18.8) - Official Zeek package for JA4+ network fingerprinting.
But I do not see any field names that look like JA4 when I try some of the test files like:
$ zeek -C -r ../ja4-main/pcap/tls3.pcapng
$ grep -ri ja ./
I tried a few different pcaps, I tried running sudo zeekctl deploy, and I tried adding the @load commands.
Not sure if I am missing something basic, I am new to both zeek and JA4. Let me know if you need any more info.
thanks,
--mark
Metadata
Metadata
Assignees
Labels
No labels