ML
    • Register
    • Login
    • Search
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups

    SIEMonster

    IT Discussion
    siem siemonster
    5
    11
    1251
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Ambarishrh
      Ambarishrh last edited by

      I was looking for a centralized log monitoring option to monitor our entire infrastructure and found this during my search

      https://n0where.net/open-source-security-incident-and-event-management

      Product https://siemonster.com

      Looks interesting

      1 Reply Last reply Reply Quote 1
      • momurda
        momurda last edited by momurda

        Cool names for their servers
        Proteus
        Tiamat
        Hydra
        Kraken
        Ikuturso

        They all seem to be named after mythical sea beasts.
        Ive not used this particular one though.

        1 Reply Last reply Reply Quote 1
        • Ambarishrh
          Ambarishrh last edited by

          I tried to run the aws image but was not successful, need to spend more time to test this.

          1 Reply Last reply Reply Quote 0
          • scottalanmiller
            scottalanmiller last edited by

            From a REALLY quick look, it looks like this is ELK+ basically? It's SIEM built on top of the ELK stack, so not reinventing the wheel, just improving it?

            JaredBusch 1 Reply Last reply Reply Quote 0
            • JaredBusch
              JaredBusch @scottalanmiller last edited by

              @scottalanmiller said in SIEMonster:

              From a REALLY quick look, it looks like this is ELK+ basically? It's SIEM built on top of the ELK stack, so not reinventing the wheel, just improving it?

              Well, there is a shitton of room to improve because it is a pain in the ass to setup a good ELK stack well.

              travisdh1 scottalanmiller 2 Replies Last reply Reply Quote 1
              • travisdh1
                travisdh1 @JaredBusch last edited by

                @jaredbusch said in SIEMonster:

                @scottalanmiller said in SIEMonster:

                From a REALLY quick look, it looks like this is ELK+ basically? It's SIEM built on top of the ELK stack, so not reinventing the wheel, just improving it?

                Well, there is a shitton of room to improve because it is a pain in the ass to setup a good ELK stack well.

                Don't remind me. Updating the Wazuh server I have running to Fedora 27 broke something with the integrations... so it remains on Fedora 26 until I can look into it further.

                1 Reply Last reply Reply Quote 0
                • scottalanmiller
                  scottalanmiller @JaredBusch last edited by

                  @jaredbusch said in SIEMonster:

                  @scottalanmiller said in SIEMonster:

                  From a REALLY quick look, it looks like this is ELK+ basically? It's SIEM built on top of the ELK stack, so not reinventing the wheel, just improving it?

                  Well, there is a shitton of room to improve because it is a pain in the ass to setup a good ELK stack well.

                  ELK is good stuff but yeah, sucks to install and has no user controls!

                  1 Reply Last reply Reply Quote 1
                  • Ambarishrh
                    Ambarishrh last edited by

                    I don't have a spare bare metal or space on VMware to test this. When I tried on aws with a medium instance; this needs 5 instances to complete the setup, i got the warning that the resources doesn't meet the requirements. Didn't get a chance to explore further

                    scottalanmiller 1 Reply Last reply Reply Quote 0
                    • scottalanmiller
                      scottalanmiller @Ambarishrh last edited by

                      @ambarishrh said in SIEMonster:

                      I don't have a spare bare metal or space on VMware to test this. When I tried on aws with a medium instance; this needs 5 instances to complete the setup, i got the warning that the resources doesn't meet the requirements. Didn't get a chance to explore further

                      Five seems excessive 🙂

                      Ambarishrh 1 Reply Last reply Reply Quote 0
                      • Ambarishrh
                        Ambarishrh last edited by

                        And from the high level design document it looks like logstash grayling and elastic

                        1 Reply Last reply Reply Quote 0
                        • Ambarishrh
                          Ambarishrh @scottalanmiller last edited by

                          @scottalanmiller said in SIEMonster:

                          @ambarishrh said in SIEMonster:

                          I don't have a spare bare metal or space on VMware to test this. When I tried on aws with a medium instance; this needs 5 instances to complete the setup, i got the warning that the resources doesn't meet the requirements. Didn't get a chance to explore further

                          Five seems excessive 🙂

                          https://vimeo.com/202195055

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post