ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    SIEMonster

    IT Discussion
    siem siemonster
    5
    11
    1.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • AmbarishrhA
      Ambarishrh
      last edited by

      I was looking for a centralized log monitoring option to monitor our entire infrastructure and found this during my search

      https://n0where.net/open-source-security-incident-and-event-management

      Product https://siemonster.com

      Looks interesting

      1 Reply Last reply Reply Quote 1
      • momurdaM
        momurda
        last edited by momurda

        Cool names for their servers
        Proteus
        Tiamat
        Hydra
        Kraken
        Ikuturso

        They all seem to be named after mythical sea beasts.
        Ive not used this particular one though.

        1 Reply Last reply Reply Quote 1
        • AmbarishrhA
          Ambarishrh
          last edited by

          I tried to run the aws image but was not successful, need to spend more time to test this.

          1 Reply Last reply Reply Quote 0
          • scottalanmillerS
            scottalanmiller
            last edited by

            From a REALLY quick look, it looks like this is ELK+ basically? It's SIEM built on top of the ELK stack, so not reinventing the wheel, just improving it?

            JaredBuschJ 1 Reply Last reply Reply Quote 0
            • JaredBuschJ
              JaredBusch @scottalanmiller
              last edited by

              @scottalanmiller said in SIEMonster:

              From a REALLY quick look, it looks like this is ELK+ basically? It's SIEM built on top of the ELK stack, so not reinventing the wheel, just improving it?

              Well, there is a shitton of room to improve because it is a pain in the ass to setup a good ELK stack well.

              travisdh1T scottalanmillerS 2 Replies Last reply Reply Quote 1
              • travisdh1T
                travisdh1 @JaredBusch
                last edited by

                @jaredbusch said in SIEMonster:

                @scottalanmiller said in SIEMonster:

                From a REALLY quick look, it looks like this is ELK+ basically? It's SIEM built on top of the ELK stack, so not reinventing the wheel, just improving it?

                Well, there is a shitton of room to improve because it is a pain in the ass to setup a good ELK stack well.

                Don't remind me. Updating the Wazuh server I have running to Fedora 27 broke something with the integrations... so it remains on Fedora 26 until I can look into it further.

                1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller @JaredBusch
                  last edited by

                  @jaredbusch said in SIEMonster:

                  @scottalanmiller said in SIEMonster:

                  From a REALLY quick look, it looks like this is ELK+ basically? It's SIEM built on top of the ELK stack, so not reinventing the wheel, just improving it?

                  Well, there is a shitton of room to improve because it is a pain in the ass to setup a good ELK stack well.

                  ELK is good stuff but yeah, sucks to install and has no user controls!

                  1 Reply Last reply Reply Quote 1
                  • AmbarishrhA
                    Ambarishrh
                    last edited by

                    I don't have a spare bare metal or space on VMware to test this. When I tried on aws with a medium instance; this needs 5 instances to complete the setup, i got the warning that the resources doesn't meet the requirements. Didn't get a chance to explore further

                    scottalanmillerS 1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller @Ambarishrh
                      last edited by

                      @ambarishrh said in SIEMonster:

                      I don't have a spare bare metal or space on VMware to test this. When I tried on aws with a medium instance; this needs 5 instances to complete the setup, i got the warning that the resources doesn't meet the requirements. Didn't get a chance to explore further

                      Five seems excessive 🙂

                      AmbarishrhA 1 Reply Last reply Reply Quote 0
                      • AmbarishrhA
                        Ambarishrh
                        last edited by

                        And from the high level design document it looks like logstash grayling and elastic

                        1 Reply Last reply Reply Quote 0
                        • AmbarishrhA
                          Ambarishrh @scottalanmiller
                          last edited by

                          @scottalanmiller said in SIEMonster:

                          @ambarishrh said in SIEMonster:

                          I don't have a spare bare metal or space on VMware to test this. When I tried on aws with a medium instance; this needs 5 instances to complete the setup, i got the warning that the resources doesn't meet the requirements. Didn't get a chance to explore further

                          Five seems excessive 🙂

                          https://vimeo.com/202195055

                          1 Reply Last reply Reply Quote 0
                          • 1 / 1
                          • First post
                            Last post