go-stash
ElastiFlow
Our great sponsors
go-stash | ElastiFlow | |
---|---|---|
5 | 31 | |
1,030 | 2,311 | |
1.6% | - | |
6.3 | 4.1 | |
4 days ago | over 2 years ago | |
Go | Shell | |
MIT License | GNU General Public License v3.0 or later |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
go-stash
ElastiFlow
- NETFLOW .. NTOPNG how to ?
- Seaching for How To install Elastiflow
-
Into my 6th year of this ... hobby?
As a matter of fact, I played with the now deprecated Elastiflow, however I couldn't get my head around managing ELK, scrapped it pretty quickly, and Netflow did not reach the meaningful stage at that time. OpenNMS looks pretty massive that I can't run it at the moment. Thanks for suggestion though.
-
Threat detection
One thing I ran for a while was security onion and utilized port mirroring to mirror the uplink port from my primary switch to my LAN on my router, so I was catching anything coming into/out of my network destined for internet. I've also used ElastiFlow ( https://github.com/robcowart/elastiflow ) which is absolutely phenomenal and awesome, I did the same and it provides some great data. You could also leverage IntelOwl ( https://github.com/intelowlproject/IntelOwl ) , one thing I have added to all my VMs is a OSSEC agent, Wazuh to be specific which is free ( https://github.com/wazuh/wazuh ) and while I am not using it to its full potential such as monitoring file deletions/modifications etc it is a powerful tool.
- Linux Network Traffic Monitor
-
Monitoring all inter-VLAN traffic on 9410 switch?
I'd recommend taking a look at Elastiflow (link is to the legacy version, I haven't used the pay structured tier version that replaced it) as a flow collector. Do it in a docker container, dump netflow to it, and use a sample rate that doesn't fill your collector box with flow packets after a single day. Depends on your traffic rates. We use 1 out of 250 for our rate.
-
Netflow bit rate and Interface Bit Rate
https://github.com/robcowart/elastiflow/issues/201 https://github.com/robcowart/elastiflow/issues/52
- Network Traffic visualization
- ElastiFlow help
-
Installation help, almost there.
Where as the newer version is (https://github.com/robcowart/elastiflow/) is called:
What are some alternatives?
dsiem - Security event correlation engine for ELK stack
ntopng - Web-based Traffic and Security Network Traffic Monitoring
o365beat - Elastic Beat for fetching and shipping Office 365 audit events
pfelk - pfSense/OPNsense + Elastic Stack
HELK - The Hunting ELK
LibreNMS - Community-based GPL-licensed network monitoring system
egopipe - A minimalist solution for logstash complexity in Elastic for Go programmers.
Netdata - The open-source observability platform everyone needs
docker-elk - The Elastic stack (ELK) powered by Docker and Compose.
loki - Like Prometheus, but for logs.
Wazuh - Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
Zabbix - Real-time monitoring of IT components and services, such as networks, servers, VMs, applications and the cloud.