Brostash
Linux distribution based on Debian and focusing on network security events collection. It comes with the following extra packages/tools:
-
Bro IDS (version: 2.5): compiled with PF_RING support.
-
PF_RING (version: 6.6.0): to speed up the packet processing.
-
Filebeat (version: 5.4): for log shipping.
Brostash offers also a build script for the raspbian lite image.