StreamAlert is a serverless, real-time data analysis framework that empowers you to ingest, analyze, and alert on data from any environment, using data sources and alerting logic you define. Computer security teams use StreamAlert to scan terabytes of log data every day for incident detection and response. Incoming log data will be classified and processed by the rules engine. Alerts are then sent to one or more outputs. Rules are written in Python; they can utilize any Python libraries or functions. Merge similar alerts and automatically promote new rules if they are not too noisy. Ingested logs and generated alerts can be retroactively searched for compliance and research. Serverless design is cheaper, easier to maintain, and scales to terabytes per day. Deployment is automated, simple, safe and repeatable for any AWS account. Secure by design, least-privilege execution, containerized analysis, and encrypted data storage.

Features

  • Fully open source and customizable
  • Built-in collection of broadly applicable community rules
  • Built-in support for dozens of log types and schemas
  • Merge similar alerts and automatically promote new rules if they are not too noisy
  • Secure by design
  • Deployment is automated

Project Samples

Project Activity

See All Activity >

License

Apache License V2.0

Follow StreamAlert

StreamAlert Web Site

Other Useful Business Software
Fully Managed MySQL, PostgreSQL, and SQL Server Icon
Fully Managed MySQL, PostgreSQL, and SQL Server

Automatic backups, patching, replication, and failover. Focus on your app, not your database.

Cloud SQL handles your database ops end to end, so you can focus on your app.
Try Free
Rate This Project
Login To Rate This Project

User Reviews

Be the first to post a review of StreamAlert!

Additional Project Details

Programming Language

Python

Related Categories

Python Frameworks, Python Information Analysis Software, Python Cloud Services Software, Python Data Analytics Tool

Registered

2022-04-01