HN Companion◀︎ back | HN Companion home | new | best | ask | show | jobs
Show HN: SIEMatic, a fair-sourced observability and security platform (github.com/mcindi)
9 points by ilovetux 19 hours ago | 6 comments


Is there a screenshot and a feature matrix of some sort? I couldn’t find on the docs site and I don’t understand what this tool is capable of, even though I’m familiar with SIEM as a general concept.

Author here: Thanks for the upvotes!

I built this so I could have an analytics, observability and security stack in my back pocket.

Individuals, nonprofit and educational users are licensed for production use.

Commercial institutions must obtain a commercial license before production use.

Have any questions, feel free to ask.


Nice work. Any plans to support OpenSearch or ClickHouse as backends in the future?

What makes this compelling over actual OSS stacks plus say Bro or some other IDS?

First, I would like to preface that this is alpha and should not replace anything in prod at the moment.

What I like about how SIEMatic is built:

* Django (personal familiarity)

* Agent, Indexer, crawlers and web all share a codebase with separate settings

* Search language is built around django orm, built-in jinja2 and ast.literal_eval makes it very versatile, I will be writing some tutorials soon

* search commands designed to handle dataframes, Django Querysets and records (lists of dicts) with predictable conversion between them (you can filter early in you search pipeline)

* from local on sqlite (rundev command) to distributed on postgres with scaling/tuning tips

* comes out of the box ready to monitor your host and provide dashboards and savedsearches

* crawlers handle data retention, alerting, summary event generation and more

There's a bunch more, but again, this is alpha software.


Someone is a fan of SIEMENS SIMATIC PLCs, it seems.