kha4w2/Windows_Log_Pipelines_Winlogbeat_Logstash_ELK-Fluent_Bit

GitHub: kha4w2/Windows_Log_Pipelines_Winlogbeat_Logstash_ELK-Fluent_Bit

面向 SOC 工程的端到端日志管道项目,整合 Winlogbeat、ELK、Fluent Bit 与 n8n SOAR,实现 Windows 安全日志的采集、分析、威胁情报富化与自动化响应。

Stars: 0 | Forks: 0

## 🔍 本仓库包含的内容 - 🖥️ **Windows → ELK 日志管道** - Winlogbeat、Logstash、Elasticsearch、Kibana - 生产就绪的配置和 SOC 用例 - 🔄 **Fluent Bit 日志处理** - 解析、过滤日志并将其摄入到 Elasticsearch - 针对性能和可扩展性进行了优化 ## 🎯 目的 提供一个集中式的 SOC 工程实验室,展示现代安全团队如何使用开源工具和自动化来收集、分析、丰富和响应安全事件。
标签:ELK日志分析, SOAR, 内容过滤, 威胁情报, 安全运营, 对抗机器学习, 开发者工具, 扫描框架, 日志收集, 越狱测试