StreamAlert Logo

StreamAlert

0
Free
Visit Website

StreamAlert is a serverless, real-time data analysis framework empowering users to ingest, analyze, and alert on data from any environment. It is used by computer security teams to scan terabytes of log data daily for incident detection and response. Rules are written in Python, logs and alerts can be retroactively searched, and deployment is automated and secure by design. It supports dozens of log types, has a collection of community rules, and is fully open source and customizable.

FEATURES

ALTERNATIVES

Standalone SIGMA-based detection tool for EVTX, Auditd, Sysmon for Linux, XML or JSONL/NDJSON Logs.

Free

Access a repository of Analytic Stories and security guides mapped to industry frameworks, with Splunk searches, machine learning algorithms, and playbooks for threat detection and response.

Free

Open source security data lake for AWS with real-time log normalization and Detection-as-Code capabilities.

Free

Graylog offers advanced log management and SIEM capabilities to enhance security and compliance across various industries.

Commercial

A collection of detections for Panther SIEM with detailed setup instructions.

Free

A dynamic GUI for advanced log analysis, allowing users to execute SQL queries on structured log data.

Free

A tool that collects and displays user activity and system events on a Windows system.

Free

A visualization app for hpfeeds logs.

Free

PINNED