kha4w2/Windows_Log_Pipelines_Winlogbeat_Logstash_ELK-Fluent_Bit
GitHub: kha4w2/Windows_Log_Pipelines_Winlogbeat_Logstash_ELK-Fluent_Bit
面向 SOC 工程的端到端日志管道项目,整合 Winlogbeat、ELK、Fluent Bit 与 n8n SOAR,实现 Windows 安全日志的采集、分析、威胁情报富化与自动化响应。
Stars: 0 | Forks: 0
## 🔍 本仓库包含的内容
- 🖥️ **Windows → ELK 日志管道**
- Winlogbeat、Logstash、Elasticsearch、Kibana
- 生产就绪的配置和 SOC 用例
- 🔄 **Fluent Bit 日志处理**
- 解析、过滤日志并将其摄入到 Elasticsearch
- 针对性能和可扩展性进行了优化
## 🎯 目的
提供一个集中式的 SOC 工程实验室,展示现代安全团队如何使用开源工具和自动化来收集、分析、丰富和响应安全事件。
标签:ELK日志分析, SOAR, 内容过滤, 威胁情报, 安全运营, 对抗机器学习, 开发者工具, 扫描框架, 日志收集, 越狱测试