Giter Club home page Giter Club logo

siemelk's Introduction

SIEMELK

SIEMELK Logo

๐Ÿ“Œ SIEMELK is a customizable and scalable Security Monitoring Software Solution that is accessible to small, medium amd enterprise organizations.

๐Ÿ“Œ SIEMELK is built on the best of Open Source tools with extra functionality, integration stability and correlation providing enriching data from the SIEM.

๐Ÿ“Œ SIEMELK IS NOT AN OPEN-SOURCE PLATFORM

Lets go beyond a SIEM

SIEMELK Architecture

SIEMELK Logo

SIEMELK Features

โœ”๏ธ Open Search for Elasticsearch + Kibana + Logstash + Filebeat

โœ”๏ธ Host and Network Threat Hunting (sysmon + wazuh)

โœ”๏ธ Embeded IDPS Service

โœ”๏ธ Netflow support

โœ”๏ธ Alerting

โœ”๏ธ Reporting

โœ”๏ธ Anomaly Detection

โœ”๏ธ Cyber Threat Intelligence

โœ”๏ธ Incident Response Integration

โœ”๏ธ Observables Analyzer

โœ”๏ธ Network Scanning module (Web-map)

โœ”๏ธ Cluster Management

โœ”๏ธ SOAR Operations

โœ”๏ธ The SIEM module supports:

  • Fortinet (Fortigate, Fortiweb)
  • Sophos (Sophos, Cyberoam)
  • Cisco (Routers, Switches, ASA, FTD, FMC)
  • Linux (security events, FIM)
  • Windows (Sysmon, Security events)
  • Netflow
  • Suricata (IDSTower + 1 year free license)
  • Host security analysis - Wazuh
  • Login bruteforce attack detection
  • MITRE ATT&CK tactics and techniques
  • Portsecurity, ARP inspection, DHCP snooping

Stack

The minimum requierments to deploy the stack:

  • 32GB of RAM + 4GB extra (Linux and services)
  • 16 Cores of CPU is Good to go.

How to choose your stack?

your stack resources depends on many factors like :

  • how many hosts do you want to monitor?
  • how many Endpoints you have?
  • how much EPS (Event Per Second) the SIEM should handle?

This table will help you to decide:

RAM CPU DISK EPS Entire Need Stack
32GB 12 1TB 3K-5K 40GB RAM Free
48GB 16 2TB 5K-10K 56GB RAM Paid
64GB 24 2TB+ 10K+ 72GB RAM paid

โš ๏ธ NOTE: The Netflow module requiers a very good performance of your machine. (SSD Disks are recommended)


Pricing

SIEMELK is free to download and use, but if you need the 100% power of SIEMELK for your SOC, then consider the table below:

Feature/Edition Free Enterprise
Platform: VM VM
Endpoints: 1-200 Up to 1K
EPS: 5K Up to 100K
Base SIEM: โœ… โœ…
Reports: โœ… โœ…
Host Intrusion Detection: โœ… โœ…
Cluster Management: โœ… โœ…
Anomaly Detection: โœ… โœ…
Alerting: โœ… โœ…
Network Scanning Module: โŒ โœ…
Network Intrusion Detection: โŒ โœ…
Upgradeable: โŒ โœ…
Kubernetes Scalable: โŒ โœ…
Threat Intelligence: โŒ โœ…
Incident Response: โŒ โœ…
SOAR: โŒ โœ…
Observability Analyzer: โŒ โœ…

license?

โœ”๏ธ To benefit the full functionality of SIEMELK

โœ”๏ธ To get technical support

โœ”๏ธ To get the last updates and special price

โœ”๏ธ We provide network architecture design and consulting for both IT and OT (SCADA), networks.

โœ”๏ธ We can help you to build your SOC (Securtiy Operations Center) based on the lastest methods available.


Download

Download The OVA template and deploy it to your VMware infrastructure.

Release Size Package
SIEMELK-v1.0 36 GB ova
Part-01 4GB
Part-02 4GB
Part-03 4GB
Part-04 4GB
Part-05 4GB
Part-06 4GB
Part-07 4GB
Part-08 4GB
Part-09 4GB

To Do

  • Adding ability to upload your configuration files from web
  • Adding ability to add replicas to your Elasticsearch form web
  • Adding Message Queuing โ€“ Kafka
  • Adding support for K8S

Contribution

If you see any bug or have something to improve SIEMELK please file an issue.

siemelk's People

Contributors

mozart4242 avatar

Watchers

 avatar

siemelk's Issues

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.