{"repo":"SuperCowPowers/zat","free":true,"listed":false,"github":"https://github.com/SuperCowPowers/zat","clone":"git clone https://github.com/SuperCowPowers/zat.git","description":"Zeek Analysis Tools (ZAT): Processing and analysis of Zeek network data with Pandas, scikit-learn, Kafka and Spark","language":"Jupyter Notebook","stars":456,"topics":["python","networking","security","bro","pandas","scikit-learn","spark","zeek","kafka","zeek-analysis"],"license":"MIT","category":"security-tools","readme_excerpt":"Zeek Analysis Tools (ZAT) The ZAT Python package supports the processing and analysis of Zeek data with Pandas, scikit-learn, Kafka, and Spark Recent Thanks to for the Dask and Polars Zeek log converters. See examples here: - Zeek to Dask - Zeek to Polars Install Getting Started - Examples of Using ZAT AWS Data Processing and ML Modeling - Please see Workbench Installing on Raspberry Pi! - Raspberry Pi Instructions Recent Improvements - Faster/Smaller Pandas Dataframes for large log files: Large Dataframes - Better Panda Dataframe to Matrix (ndarray) support: Dataframe To Matrix - Scalable conversion from Zeek logs to Parquet: Zeek to Parquet - Vastly improved Spark Dataframe Class: Zeek to Spark - Updated/improved Notebooks: Analysis Notebooks - Zeek JSON to DataFrame class: Zeek JSON to DataFrame Example Video Presentation - Data Analysis and Machine Learning with Zeek Why ZAT? Zeek already has a flexible, powerful scripting language why should I use ZAT? Offloading: Running complex tasks like statistics, state machines, machine learning, etc.. should be offloaded from Zeek so that Zeek can focus on the efficient processing of high volume network traffic. Data Analysis: We have a large set of support classes that help bridge from raw Zeek data to packages like Pandas, scikit-learn, Kafka, and Spark. We also have example notebooks that show step-by-step how to get from here to there. Analysis Notebooks - Zeek to Scikit-Learn - Zeek to Parquet - Zeek to Spark - Spark Clusteri","default_branch":null,"files":null,"tree":[],"storefront":"/r/SuperCowPowers","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/SuperCowPowers/zat/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}