-
Notifications
You must be signed in to change notification settings - Fork 81
Home
V1D1AN edited this page May 24, 2021
·
21 revisions
Welcome to the S1EM wiki!
This project is a SIEM with SIRP and Threat Intel,all in one.
Solution work with CentOS 7 and kernel 5 ( For Auditbeat ), and docker.
Inside the solution:
- Elasticsearch
- Kibana
- Filebeat
- Logstash
- Metricbeat
- Auditbeat
- Elastalert
- TheHive
- Cortex
- MISP
- OpenCTI
- Suricata 5
- Zeek 3
- FleetDm
- StoQ
- Heimdall
- Traefik
Note: Cortex v3.1 use ELK connector and the OpenCTI v4 connector
You must have:
- 12 Go Ram
- 75 Go DD
- 8 cpu
- 1 network for monitoring
You must have:
- 32 Go Ram
- More than 75 Go DD
- 8 cpu
- 1 network for monitoring