Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Log analysis and visualization tool #58

Open
paseaf opened this issue Aug 10, 2022 · 0 comments
Open

Log analysis and visualization tool #58

paseaf opened this issue Aug 10, 2022 · 0 comments
Assignees
Labels
audit log everything related to honeypot audit logs data anlaysis

Comments

@paseaf
Copy link
Owner

paseaf commented Aug 10, 2022

Problem

Currently, each time we want to find some insight from the audit logs, we need to write SQL.
It's not fast, and does not directly provide visualization.

Goal

  1. Visualization for log analysis
    Find a tool that provides interactive graphical query and visualization.
    It should also provide a web interface so we can later set up on the cloud and access from our local machines in real time

  2. Visualization to reflect/replay attacker locations and attack steps

Possible steps

  1. find out relevant tools
  2. evaluate

Possible tools:

Apache Superset
https://superset.apache.org/

Note:
Can we get the password list they use by disabling user login?

@paseaf paseaf self-assigned this Aug 10, 2022
@paseaf paseaf added audit log everything related to honeypot audit logs data anlaysis labels Aug 10, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
audit log everything related to honeypot audit logs data anlaysis
Projects
None yet
Development

No branches or pull requests

1 participant