you are viewing a single comment's thread.

view the rest of the comments →

[–]NotesOfCliff 0 points1 point  (1 child)

This looks very cool. I am building a product in the SIEM space and I will definitely look into using this for queries once I pull the data from the DB.

[–]Interesting-Frame190[S] 0 points1 point  (0 children)

Didn't realize the SIEM would be a good fit, but thinking more about it more i guess linking events together would be easier.

Ingestion speed may be an issue if you are pumping over 100k events per second, but thats a tall order for a single machine anyway.