← Package directory
Available on winget

Install Brim

Desktop application to efficiently search large packet captures and Zeek logs.

Install with winget
winget install --id brimdata.brim
Upgrade
winget upgrade --id brimdata.brim
Uninstall
winget uninstall --id brimdata.brim

About Brim

Desktop application to efficiently search large packet captures and Zeek logs.

What's new in 1.18.0

Visit the Brim Data download page page to find the package for your platform. - Update Zed to v1.18.0 - Update Brimcap to v1.18.0, which includes a new Zeek v7.0.0-brim1 - Introduce the Sessions tab in the left panel to persist Query Session histories (#3132) - Update time display functionality to support local time zones and strftime directives (#3139) - Fix an issue where the Zui window could not be dragged when Preview & Load was open (#3146) - Fix a crash that would occur when attempting to create a pool with the same name as an existing pool (#3147) - Fix an issue where top-level primitive Zed values were incorrectly wrapped in records in the Table view (#3145, #3150)

Read release notes

Version history

Version Updated Notes
1.18.0 Unknown Visit the Brim Data download page page to find the package for your platform. - Update Zed to v1.18.0 - Update Brimcap to v1.18.0, which includes a new Zeek v7.0.0-brim1 - Introduce the Sessions tab in the left panel to...
1.7.0 Unknown Release notes
1.6.0 Unknown Release notes
1.5.0 Unknown Release notes
1.4.1 Unknown - Update Zed to v1.11.1
1.4.0 Unknown Other Changes - Update Zed to v1.11.0 - Update Brimcap to v1.5.3 - Zui has a new Preview & Load workflow that allows for shaping data as it's loaded in to a Zed lake (#2834, #2864) - Fix an issue where editing the "month...
1.3.1 Unknown - Due to malware false positives, Windows releases no longer include a full initial set of Suricata rules (as always, up-to-date rules will be downloaded on first Internet-connected launch of Zui) (#2858)
1.3.0 Unknown Other Changes - Update Zed to v1.10.0 - Update Brimcap to v1.5.2 - The Zui GitHub repo is now structured as a monorepo (#2818) - Fix an issue where a community_id field was incorrectly being treated as a prerequisite to...
1.2.0 Unknown - Any time field can be specified (and if you've configured a pool key other than ts, it will start out using that) - count() by typeof(this) now populates the stacked bars by default, but you can change this to use any...
1.1.0 Unknown - Update Zed to v1.8.0 - Update Brimcap to v1.5.0 - Restore "alert" tiles for Suricata events (#2740) - Fix an issue where use of Chinese and other wide characters caused errors during data import (#2744) - Fix an issue...
1.0.1 Unknown Release notes
1.0.0 Unknown Release notes
0.31.0 Unknown Release notes
0.30.0 Unknown Release notes
0.29.0 Unknown Release notes
0.28.0 Unknown No notes
0.27.0 Unknown No notes
0.26.0 Unknown No notes
0.25.0 Unknown No notes
0.24.0 Unknown No notes