Skip to main content
Advanced Search
Search Terms
Content Type

Exact Matches
Tag Searches
Date Options
Updated after
Updated before
Created after
Created before

Search Results

62 total results found

Architecture

Homebrew SIEM

The whole system is four stages in a line: collect, centralize, analyze, alert. Every later page is one of these stages in detail. The pipeline Collect. Every host generates logs already; authentication attempts, firewall decisions, service errors, system mess...

Collection

Homebrew SIEM

Pattern: getting logs off every host and into one place. This is the plumbing, getting this stage right is what everything else depends on. The mechanism is the standard Linux system logger (rsyslog), configured on each host to forward, and on one central host...

What to Monitor

Homebrew SIEM

Pattern: deciding what is worth watching. This is the judgment page, and it is deliberately general. It walks the categories worth monitoring and the reasoning for each, without the thresholds or exact detection logic, because those are the part that helps an ...

Analysis

Homebrew SIEM

Pattern: turning collected logs into signals. Collection gathers raw logs, analysis reduces them to the handful of statements worth acting on. This page shows one category in full, health monitoring, chosen because it is operational rather than a detection tri...

Alerting and Scheduling

Homebrew SIEM

Pattern: getting signals to a human, on a cadence. Analysis produces signals, this stage runs the analysis on a schedule and delivers whatever warrants attention. There are two ways to do it, a scheduler and a script, or a dedicated automation platform, and th...

Operations

Homebrew SIEM

A monitoring system that is installed and never tended decays into either noise you ignore or silence you trust wrongly. Operating it means two things: keep the alerts meaningful, and make sure the monitor itself is still working. Tuning out noise The failure ...

Lessons Learned

Homebrew SIEM

The lessons I've learned from building basic security monitoring without a SIEM product. You don't need a SIEM product to have a SIEM. The function, collect, centralize, analyze, alert, is achievable with the system logger, a few scripts, and a scheduler. The ...

Use it or Lose it - AI and the Atrophy of Skill

Use it or Lose it - AI and the Atrophy ...

Forward Years ago I managed a small team of talented developers where writing SQL was a large part of the job. The team's SQL experience varied, some were early in building it and some were fairly advanced, and part of my role was reviewing queries they were w...