chuck-confluent / demo-siem-optimization

This demo illustrates how to use Confluent to optimize your Security Information and Event Management (SIEM) solution. Active Development is occurring on https://github.com/confluentinc/demo-siem-optimization.
0 stars 6 forks source link

DEPRECATED

Active development on this demo is now taking place at https://github.com/confluentinc/demo-siem-optimization. Cheers!

Optimize SIEM With Confluent

The examples in this repository give you hands-on experience optimizing Security Information and Event Management (SIEM) solutions using Confluent. Each tutorial illustrates how to use Confluent to improve the response to a common cybersecurity scenario.

Hands-On in Your Browser

This demo runs best using Gitpod. Gitpod uses your existing git service account (GitHub, Gitlab, or BitBucket) for authentication. See the gitpod tips to get acquainted with gitpod.

Launch a workspace to get hands-on with the labs:

If you want to run locally or in a different environment, see the appendix.

Hands-On Lab Instructions

Run through entire end-to-end demo to get the big picture. Zoom in on the individual labs to go into more detail.

  1. End-to-End Demo (long)
  2. Introduction
  3. Analyze Syslog Data in Real Time with ksqlDB
  4. Calculate Hourly Bandwidth Usage By Host with ksqlDB
  5. Match Hostnames in a Watchlist Against Streaming DNS Data
  6. Filter SSL Transactions and Enrich with Geospatial Data

References

Demo Video

Executive Brief

Cyber Defense Whitepaper

Confluent Sigma