Skip to content

This demo illustrates how to use Confluent to optimize your Security Information and Event Management (SIEM) solution.

Notifications You must be signed in to change notification settings

Android-L-Porting-Team/demo-siem-optimization

 
 

Repository files navigation

Optimize SIEM With Confluent

The examples in this repository give you hands-on experience optimizing Security Information and Event Management (SIEM) solutions using Confluent. Each tutorial illustrates how to use Confluent to improve the response to a common cybersecurity scenario.

Hands-On in Your Browser

This demo runs best using Gitpod. Gitpod uses your existing git service account (GitHub, Gitlab, or BitBucket) for authentication. See the gitpod tips to get acquainted with gitpod.

Launch a workspace to get hands-on with the labs:

If you want to launch a workspace that automatically submits all connectors, use this link instead:

If you want to run locally or in a different environment, see the appendix.

Hands-On Lab Instructions

Run through entire end-to-end demo to get the big picture. Zoom in on the individual labs to go into more detail.

  1. End-to-End Demo (long)
  2. Introduction
  3. Analyze Syslog Data in Real Time with ksqlDB
  4. Calculate Hourly Bandwidth Usage By Host with ksqlDB
  5. Match Hostnames in a Watchlist Against Streaming DNS Data
  6. Filter SSL Transactions and Enrich with Geospatial Data

References

Demo Video

Executive Brief

Cyber Defense Whitepaper

Confluent Sigma

About

This demo illustrates how to use Confluent to optimize your Security Information and Event Management (SIEM) solution.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • Zeek 60.9%
  • Shell 27.4%
  • Python 6.6%
  • Dockerfile 5.1%