diff --git a/salt/zeek/soc_zeek.yaml b/salt/zeek/soc_zeek.yaml index a3ad624b6..8410d4e75 100644 --- a/salt/zeek/soc_zeek.yaml +++ b/salt/zeek/soc_zeek.yaml @@ -1,4 +1,7 @@ zeek: + enabled: + description: You can enable or disable ZEEK on all sensors or a single sensor. + helpLink: zeek.html logging: enabled: description: This is a list of Zeek logs that will be shipped through the pipeline. If you remove a log from this list, it will still persist on the sensor.