ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    SIEMonster

    IT Discussion
    siem siemonster
    5
    11
    1.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • momurdaM
      momurda
      last edited by momurda

      Cool names for their servers
      Proteus
      Tiamat
      Hydra
      Kraken
      Ikuturso

      They all seem to be named after mythical sea beasts.
      Ive not used this particular one though.

      1 Reply Last reply Reply Quote 1
      • AmbarishrhA
        Ambarishrh
        last edited by

        I tried to run the aws image but was not successful, need to spend more time to test this.

        1 Reply Last reply Reply Quote 0
        • scottalanmillerS
          scottalanmiller
          last edited by

          From a REALLY quick look, it looks like this is ELK+ basically? It's SIEM built on top of the ELK stack, so not reinventing the wheel, just improving it?

          JaredBuschJ 1 Reply Last reply Reply Quote 0
          • JaredBuschJ
            JaredBusch @scottalanmiller
            last edited by

            @scottalanmiller said in SIEMonster:

            From a REALLY quick look, it looks like this is ELK+ basically? It's SIEM built on top of the ELK stack, so not reinventing the wheel, just improving it?

            Well, there is a shitton of room to improve because it is a pain in the ass to setup a good ELK stack well.

            travisdh1T scottalanmillerS 2 Replies Last reply Reply Quote 1
            • travisdh1T
              travisdh1 @JaredBusch
              last edited by

              @jaredbusch said in SIEMonster:

              @scottalanmiller said in SIEMonster:

              From a REALLY quick look, it looks like this is ELK+ basically? It's SIEM built on top of the ELK stack, so not reinventing the wheel, just improving it?

              Well, there is a shitton of room to improve because it is a pain in the ass to setup a good ELK stack well.

              Don't remind me. Updating the Wazuh server I have running to Fedora 27 broke something with the integrations... so it remains on Fedora 26 until I can look into it further.

              1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller @JaredBusch
                last edited by

                @jaredbusch said in SIEMonster:

                @scottalanmiller said in SIEMonster:

                From a REALLY quick look, it looks like this is ELK+ basically? It's SIEM built on top of the ELK stack, so not reinventing the wheel, just improving it?

                Well, there is a shitton of room to improve because it is a pain in the ass to setup a good ELK stack well.

                ELK is good stuff but yeah, sucks to install and has no user controls!

                1 Reply Last reply Reply Quote 1
                • AmbarishrhA
                  Ambarishrh
                  last edited by

                  I don't have a spare bare metal or space on VMware to test this. When I tried on aws with a medium instance; this needs 5 instances to complete the setup, i got the warning that the resources doesn't meet the requirements. Didn't get a chance to explore further

                  scottalanmillerS 1 Reply Last reply Reply Quote 0
                  • scottalanmillerS
                    scottalanmiller @Ambarishrh
                    last edited by

                    @ambarishrh said in SIEMonster:

                    I don't have a spare bare metal or space on VMware to test this. When I tried on aws with a medium instance; this needs 5 instances to complete the setup, i got the warning that the resources doesn't meet the requirements. Didn't get a chance to explore further

                    Five seems excessive 🙂

                    AmbarishrhA 1 Reply Last reply Reply Quote 0
                    • AmbarishrhA
                      Ambarishrh
                      last edited by

                      And from the high level design document it looks like logstash grayling and elastic

                      1 Reply Last reply Reply Quote 0
                      • AmbarishrhA
                        Ambarishrh @scottalanmiller
                        last edited by

                        @scottalanmiller said in SIEMonster:

                        @ambarishrh said in SIEMonster:

                        I don't have a spare bare metal or space on VMware to test this. When I tried on aws with a medium instance; this needs 5 instances to complete the setup, i got the warning that the resources doesn't meet the requirements. Didn't get a chance to explore further

                        Five seems excessive 🙂

                        https://vimeo.com/202195055

                        1 Reply Last reply Reply Quote 0
                        • 1 / 1
                        • First post
                          Last post