LOG SOURCES
ETL — INGESTION
HOT PATH — DETECTION & RESPONSE · 2 MONTHS
COLD PATH — BIG DATA · 2 YEARS · 2 PB
LEGAL PATH
TRANSVERSE
deploys & monitors every cluster
Windows
Audit logs · Sysmon
Linux
rsyslog
Beats agents
Filebeat · Fluent Bit
NIDS
Suricata · Snort
Firewalls
Stormshield · Arkoon
Web servers
access / error
Mail servers
SMTP / IMAP
File shares
Samba · SharePoint
Logstash #1
normalization
syslog + JSON
→ RFC 5424
Kafka
streaming bus
retention buffer
topic: logs-raw
ksqlDB
categorization
splits per source
fw · nids · win …
Logstash #2
KV parse RFC 5424
GeoIP · CTI · assets
Elasticsearch
index per stream
ILM hot/warm · 2 mo
Kibana
dashboards
Sigma rule alerts
TheHive
SOC cases
Cortex
auto-response
Hadoop HDFS
legal retention 2 y
~2 PB
Spark
MapReduce batch
hunting at scale
Legal team stack
independent consumer
chain of custody · forensics
IaC
GitLab CI/CD
+ Ansible
Monitoring
Prometheus
+ Grafana
RFC 5424
hot
cold
legal
Sigma alerts
LEGEND
Ingestion
Hot path · detection
Cold path · big data
Legal path
Alerts & response
Deploy & monitor
Text is not SVG - cannot display