Wednesday, July 24, 2019

SELKS: Suricata IDS powered by the ELK

SELKS is a fantastic network-based intrusion detection system. It uses Suricata as the IDS engine, as well as the Elasticsearch/Logstash/Kibana (ELK) as the log management system. I've teste the 4th version, although today it's 5th version is stable. As I remember, installation of the VM distribution is straight, configuring the ELK subsystem is somehow tricky, while the other subsystems are easy to set up. You can enjoy pre-built dashboards, and also can build your own ones.

No comments:

Post a Comment