Forwarders, Agents, Sources, Sensors:
Enrichment, Normalization, Parsing:
Collectors, Ingesters, Aggregators:
Indexers, Storage Nodes, Search Nodes:
Beats
Logstash
Elasticsearch
Kibana
(Agents)
(Enrichment)
(Indexing)
(Visualization)
Zeek
ElastAlert
(Network Monitor)
(Alerting)
Network Logger
Workstation
Workstation
Workstation
Storage / DB
Dashboards
Searching
Reporting
Zeek
ElastAlert
(Network Monitor)
(Alerting)
Beats
Logstash
Elasticsearch
Kibana
(Agents)
(Enrichment)
(Indexing)
(Visualization)
https://asciinema.org/a/0UfptVlhWSEKyYB68rEH1AIaG
https://asciinema.org/a/I6mL9FsSmCLakXvi7h8WK5NiU
https://slides.com/cronocide/building-your-first-siem
https://www.cronocide.com/post/byfswtes/