Monitor: Audit Logging & Threat Intel
Audit logging, STIX/TAXII threat-intelligence matching, and SIEM log ingest.
- Collectors for auditd, syslog, journald, file-based logs, Kubernetes, LXC, and database-sourced events.
- A dedicated threat-intel matcher ingests STIX-formatted intelligence over TAXII feeds and correlates it against the collected event stream.
- A separate Logs service OCSF-normalizes incoming events and bulk-indexes them into OpenSearch. Dashboards and alerts surface matches for investigation.