Skip to content

Latest commit

 

History

History
44 lines (26 loc) · 1.91 KB

README.md

File metadata and controls

44 lines (26 loc) · 1.91 KB

Optimize SIEM With Confluent

The examples in this repository give you hands-on experience optimizing Security Information and Event Management (SIEM) solutions using Confluent. Each tutorial illustrates how to use Confluent to improve the response to a common cybersecurity scenario.

Hands-On in Your Browser

This demo runs best using Gitpod. Gitpod uses your existing git service account (GitHub, Gitlab, or BitBucket) for authentication. See the gitpod tips to get acquainted with gitpod.

Launch a workspace to get hands-on with the labs:

If you want to launch a workspace that automatically submits all connectors, use this link instead:

If you want to run locally or in a different environment, see the appendix.

Hands-On Lab Instructions

Run through entire end-to-end demo to get the big picture. Zoom in on the individual labs to go into more detail.

  1. End-to-End Demo (long)
  2. Introduction
  3. Analyze Syslog Data in Real Time with ksqlDB
  4. Calculate Hourly Bandwidth Usage By Host with ksqlDB
  5. Match Hostnames in a Watchlist Against Streaming DNS Data
  6. Filter SSL Transactions and Enrich with Geospatial Data

References

Demo Video

Executive Brief

Cyber Defense Whitepaper

Confluent Sigma