dovehawk_flow Anonymized Outgoing Flow Collector Module for Zeek

This module collects outgoing flow counts to external IPs across an entire Cluster or Standalone Zeek instance. The local source IPs are not tracked and SUMSTATS is used to sum multiple requests over a specified time period anonymizing and grouping the requests across the entire network.

Local hostnames are stripped to further anonymize the data for external sharing.

Sticker 1 Sticker 2


DoveHawk Flow Reported

Dovehawk Flow Reports

DoveHawk flow.log Local Log

Dovehawk Flow Log


Zeek > 3.0

Curl command line version used by ActiveHTTP


See dovehawk_lambda for an AWS Lambda serverless function to store reporting in RDS Aurora.



Package Version :