TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Elastic SIEM – Security Information and Event Management

89 pointsby praseodymalmost 6 years ago

6 comments

strictneinalmost 6 years ago
&gt; SIEM detection rules ... on our roadmap<p>The current solution in this space, that actually works really well at scale, is ElastAlert[0]. The problem is that ElastAlert is kind of a mess to work with. Lots of documentation, but you need to get into the weeds with it to figure out how it really functions.<p>Once you get it going it&#x27;s a great tool. Scaling it out (we run hundreds of rules pretty frequently - upwards of 15 times an hour) is just standing up more instances with their own separate rules.<p>[0] <a href="https:&#x2F;&#x2F;github.com&#x2F;Yelp&#x2F;elastalert" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;Yelp&#x2F;elastalert</a>
评论 #20311013 未加载
jamestimminsalmost 6 years ago
I always find that Elastic assumes decent familiarity with their products even when &quot;introducing&quot; them. Everything looks beautiful but I can&#x27;t quite tell what different tools do.
评论 #20279294 未加载
DeepYogurtalmost 6 years ago
So for those interested Mozilla is working on something pretty similar.<p><a href="https:&#x2F;&#x2F;mozdef.readthedocs.io&#x2F;en&#x2F;latest&#x2F;" rel="nofollow">https:&#x2F;&#x2F;mozdef.readthedocs.io&#x2F;en&#x2F;latest&#x2F;</a><p>They have a set of docker containers which I find very handy for spinning up deploy specific logging sinks or full on SIEMs.
评论 #20280758 未加载
pingecalmost 6 years ago
Seems like the natural evolution of the already popular ELK stack. I hope they add popular siem features like archiving, alerting, central configuration management etc. I&#x27;ll stick with graylog for now.
评论 #20279725 未加载
msandfordalmost 6 years ago
Does anyone know what SIEM is? It&#x27;s said multiple times in the article but never defined that I could see.
评论 #20279218 未加载
评论 #20279059 未加载
评论 #20282633 未加载
评论 #20279676 未加载
评论 #20280695 未加载
评论 #20279466 未加载
评论 #20279095 未加载
评论 #20281639 未加载
评论 #20279060 未加载
bryanrasmussenalmost 6 years ago
I was at a workshop a couple days ago, pretty worthwhile and they were pretty excited about something coming out in security - I guess this is it.<p>Seems a logical progression from Kibana and Logstash - but sometimes I worry search will suffer for all this other stuff.
评论 #20279595 未加载