idaholab / Malcolm

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
https://idaholab.github.io/Malcolm/
Other
327 stars 53 forks source link

create dashboards for other non-network log data #414

Closed mmguero closed 4 months ago

mmguero commented 4 months ago

Malcolm can accept various third-party logs, and while there's no way we could create dashboards for every conceivable source, we could create them for more than we have.

We have some already (mainly used for data coming from Hedgehog):

image

But there are lots of others we could/should create dashboards for, potentially including:

mmguero commented 4 months ago

I've either ensured we have existing dashboards or created new ones for the following inputs. It is true that I haven't covered every possible fluent-bit input, but I think this is good for now. We may revisit later if there is more interest (esp., perhaps the docker, podman and kubernetes events ones).

Fluent Bit inputs

Zeek diagnostics

Suricata Stats

mmguero commented 4 months ago

Here's a dashboard for Packet Capture Statistics:

Screenshot 2024-03-01 at 12-20-29 Packet Capture Statistics - Malcolm Dashboards