Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

agnos.is Forums

  1. Home
  2. Selfhosted
  3. SEIM

SEIM

Scheduled Pinned Locked Moved Selfhosted
selfhosted
13 Posts 9 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • nagaram@startrek.websiteN This user is from outside of this forum
    nagaram@startrek.websiteN This user is from outside of this forum
    [email protected]
    wrote on last edited by
    #1

    I am studying for my Network+ and my Sec+ hoping to shadow our Cyber Sec guy at work.

    I want to set up a SEIM on my home network so I can be used to it's operations and how it works by the time I start messing with Pentesting stuff. Then I'm going to use it to try and track myself when I pentest myself.

    I was looking into Graylog or Security Onion since they seem to have decent documentation (and I can find videos on how to set them up which is nice).

    I was recommended building my own ELK stack and doing everything manually for maximum learning potential. Which I understand why this is a good idea, but I think I'd rather be as close to "baby's first SEIM" as possible or at least have a robust how-to guide.

    What do you suggest?

    L randomcruft@lemmy.sdf.orgR M M C 7 Replies Last reply
    1
    0
    • System shared this topic on
    • nagaram@startrek.websiteN [email protected]

      I am studying for my Network+ and my Sec+ hoping to shadow our Cyber Sec guy at work.

      I want to set up a SEIM on my home network so I can be used to it's operations and how it works by the time I start messing with Pentesting stuff. Then I'm going to use it to try and track myself when I pentest myself.

      I was looking into Graylog or Security Onion since they seem to have decent documentation (and I can find videos on how to set them up which is nice).

      I was recommended building my own ELK stack and doing everything manually for maximum learning potential. Which I understand why this is a good idea, but I think I'd rather be as close to "baby's first SEIM" as possible or at least have a robust how-to guide.

      What do you suggest?

      L This user is from outside of this forum
      L This user is from outside of this forum
      [email protected]
      wrote on last edited by
      #2

      SEIM? Do you mean SIEM, Secure Information and Event Management?

      nagaram@startrek.websiteN 1 Reply Last reply
      0
      • nagaram@startrek.websiteN [email protected]

        I am studying for my Network+ and my Sec+ hoping to shadow our Cyber Sec guy at work.

        I want to set up a SEIM on my home network so I can be used to it's operations and how it works by the time I start messing with Pentesting stuff. Then I'm going to use it to try and track myself when I pentest myself.

        I was looking into Graylog or Security Onion since they seem to have decent documentation (and I can find videos on how to set them up which is nice).

        I was recommended building my own ELK stack and doing everything manually for maximum learning potential. Which I understand why this is a good idea, but I think I'd rather be as close to "baby's first SEIM" as possible or at least have a robust how-to guide.

        What do you suggest?

        randomcruft@lemmy.sdf.orgR This user is from outside of this forum
        randomcruft@lemmy.sdf.orgR This user is from outside of this forum
        [email protected]
        wrote on last edited by
        #3

        Just a suggestion but take a look at this list… all of them should be either open source or at least free (trials, lite versions, etc.).

        Find out what you use at work and see if there’s a trial version or if they use open source.

        If not most of these tools are known and you may be able to find help online (forums, Lemmy, Reddit, etc.).

        https://www.dnsstuff.com/free-siem-tools

        1 Reply Last reply
        0
        • L [email protected]

          SEIM? Do you mean SIEM, Secure Information and Event Management?

          nagaram@startrek.websiteN This user is from outside of this forum
          nagaram@startrek.websiteN This user is from outside of this forum
          [email protected]
          wrote on last edited by
          #4

          Yes! Gods damn it. I had that up an everything on my second monitor.

          shimitar@downonthestreet.euS 1 Reply Last reply
          0
          • nagaram@startrek.websiteN [email protected]

            I am studying for my Network+ and my Sec+ hoping to shadow our Cyber Sec guy at work.

            I want to set up a SEIM on my home network so I can be used to it's operations and how it works by the time I start messing with Pentesting stuff. Then I'm going to use it to try and track myself when I pentest myself.

            I was looking into Graylog or Security Onion since they seem to have decent documentation (and I can find videos on how to set them up which is nice).

            I was recommended building my own ELK stack and doing everything manually for maximum learning potential. Which I understand why this is a good idea, but I think I'd rather be as close to "baby's first SEIM" as possible or at least have a robust how-to guide.

            What do you suggest?

            M This user is from outside of this forum
            M This user is from outside of this forum
            [email protected]
            wrote on last edited by
            #5

            I suggest skipping the devops part and instead starting with a course. If you go with setting it up you will probably spend 95% of the time doing devops and not security (which is usually the client of the devops team that maintains the SIEM)

            nagaram@startrek.websiteN 1 Reply Last reply
            0
            • nagaram@startrek.websiteN [email protected]

              I am studying for my Network+ and my Sec+ hoping to shadow our Cyber Sec guy at work.

              I want to set up a SEIM on my home network so I can be used to it's operations and how it works by the time I start messing with Pentesting stuff. Then I'm going to use it to try and track myself when I pentest myself.

              I was looking into Graylog or Security Onion since they seem to have decent documentation (and I can find videos on how to set them up which is nice).

              I was recommended building my own ELK stack and doing everything manually for maximum learning potential. Which I understand why this is a good idea, but I think I'd rather be as close to "baby's first SEIM" as possible or at least have a robust how-to guide.

              What do you suggest?

              M This user is from outside of this forum
              M This user is from outside of this forum
              [email protected]
              wrote on last edited by
              #6

              Wazuh is popular. It's in use by name brand companies and is FOSS.

              Graylog is also a popular option.

              1 Reply Last reply
              1
              0
              • nagaram@startrek.websiteN [email protected]

                I am studying for my Network+ and my Sec+ hoping to shadow our Cyber Sec guy at work.

                I want to set up a SEIM on my home network so I can be used to it's operations and how it works by the time I start messing with Pentesting stuff. Then I'm going to use it to try and track myself when I pentest myself.

                I was looking into Graylog or Security Onion since they seem to have decent documentation (and I can find videos on how to set them up which is nice).

                I was recommended building my own ELK stack and doing everything manually for maximum learning potential. Which I understand why this is a good idea, but I think I'd rather be as close to "baby's first SEIM" as possible or at least have a robust how-to guide.

                What do you suggest?

                C This user is from outside of this forum
                C This user is from outside of this forum
                [email protected]
                wrote on last edited by
                #7

                Wazuh if you want a product instead of building it from scratch.

                I'd give Greenbone a try too, I think it's most analogous to Nessus.

                1 Reply Last reply
                0
                • nagaram@startrek.websiteN [email protected]

                  Yes! Gods damn it. I had that up an everything on my second monitor.

                  shimitar@downonthestreet.euS This user is from outside of this forum
                  shimitar@downonthestreet.euS This user is from outside of this forum
                  [email protected]
                  wrote on last edited by
                  #8

                  You can edit your posts, you know 🙂

                  nagaram@startrek.websiteN 1 Reply Last reply
                  0
                  • shimitar@downonthestreet.euS [email protected]

                    You can edit your posts, you know 🙂

                    nagaram@startrek.websiteN This user is from outside of this forum
                    nagaram@startrek.websiteN This user is from outside of this forum
                    [email protected]
                    wrote on last edited by
                    #9

                    Thanks! I'm still on reddit brain.

                    1 Reply Last reply
                    0
                    • M [email protected]

                      I suggest skipping the devops part and instead starting with a course. If you go with setting it up you will probably spend 95% of the time doing devops and not security (which is usually the client of the devops team that maintains the SIEM)

                      nagaram@startrek.websiteN This user is from outside of this forum
                      nagaram@startrek.websiteN This user is from outside of this forum
                      [email protected]
                      wrote on last edited by
                      #10

                      Got any recs? I can generally talk my company into paying for most anything education wise, but Udemy style courses work with my ADHD the best.

                      M 1 Reply Last reply
                      0
                      • nagaram@startrek.websiteN [email protected]

                        Got any recs? I can generally talk my company into paying for most anything education wise, but Udemy style courses work with my ADHD the best.

                        M This user is from outside of this forum
                        M This user is from outside of this forum
                        [email protected]
                        wrote on last edited by
                        #11

                        Nothing that comes to mind, but simple search of the SIEM you are going to use in youtube and pirate bay should provide some good starters

                        1 Reply Last reply
                        0
                        • nagaram@startrek.websiteN [email protected]

                          I am studying for my Network+ and my Sec+ hoping to shadow our Cyber Sec guy at work.

                          I want to set up a SEIM on my home network so I can be used to it's operations and how it works by the time I start messing with Pentesting stuff. Then I'm going to use it to try and track myself when I pentest myself.

                          I was looking into Graylog or Security Onion since they seem to have decent documentation (and I can find videos on how to set them up which is nice).

                          I was recommended building my own ELK stack and doing everything manually for maximum learning potential. Which I understand why this is a good idea, but I think I'd rather be as close to "baby's first SEIM" as possible or at least have a robust how-to guide.

                          What do you suggest?

                          C This user is from outside of this forum
                          C This user is from outside of this forum
                          [email protected]
                          wrote on last edited by
                          #12

                          I would look at CISA’s Logging Made Easy project, which is based on Wazuh and Elastic with Kibana for visualization and dashboards.

                          https://github.com/cisagov/LME

                          1 Reply Last reply
                          0
                          • nagaram@startrek.websiteN [email protected]

                            I am studying for my Network+ and my Sec+ hoping to shadow our Cyber Sec guy at work.

                            I want to set up a SEIM on my home network so I can be used to it's operations and how it works by the time I start messing with Pentesting stuff. Then I'm going to use it to try and track myself when I pentest myself.

                            I was looking into Graylog or Security Onion since they seem to have decent documentation (and I can find videos on how to set them up which is nice).

                            I was recommended building my own ELK stack and doing everything manually for maximum learning potential. Which I understand why this is a good idea, but I think I'd rather be as close to "baby's first SEIM" as possible or at least have a robust how-to guide.

                            What do you suggest?

                            ? Offline
                            ? Offline
                            Guest
                            wrote on last edited by
                            #13

                            Grafana Loki is very light on resources and simple to deploy in most cases.

                            Combine with Sigma detection rules (converted to LogQL queries using the Loki plugin) and you're off to the races.

                            1 Reply Last reply
                            0
                            • System shared this topic on
                            Reply
                            • Reply as topic
                            Log in to reply
                            • Oldest to Newest
                            • Newest to Oldest
                            • Most Votes


                            • Login

                            • Login or register to search.
                            • First post
                              Last post
                            0
                            • Categories
                            • Recent
                            • Tags
                            • Popular
                            • World
                            • Users
                            • Groups