Monitor: Audit Logging & Threat Intel

Audit logging, STIX/TAXII threat-intelligence matching, and SIEM log ingest.

  • Collectors for auditd, syslog, journald, file-based logs, Kubernetes, LXC, and database-sourced events.
  • A dedicated threat-intel matcher ingests STIX-formatted intelligence over TAXII feeds and correlates it against the collected event stream.
  • A separate Logs service OCSF-normalizes incoming events and bulk-indexes them into OpenSearch. Dashboards and alerts surface matches for investigation.

← Back to all features

Full technical documentation →