IRCC lab / Security logs

The community SIEM.

We use Axiom as our SIEM, bringing together AWS management events and systemd and audit logs from our on-prem Linux servers.

A place to investigate activity, try out detection ideas and learn from real systems.

Where the data goes

Cloud

AWS

All management events

On-prem servers

Linux

All systemd + audit logs

Web traffic

Cloudflare

Sampled analytics

Axiom

SIEM / Search and analysis

AWS and Linux logs, plus sampled Cloudflare analytics, flow into Axiom. Illustrated data flow, not live telemetry.

AWS management events

All AWS management events are sent to Axiom. These record control-plane activity, such as API calls that create, change or inspect AWS resources.

Linux systemd and audit logs

Our local Linux servers send all their systemd journal and audit logs. The journals contain service and system messages; audit logs record activity captured by the servers’ audit rules.

Cloudflare analytics

Cloudflare sends traffic summaries, sampled HTTP requests and available security events into Axiom through a scheduled analytics collector. These help us investigate web traffic and security activity, but they are not a complete HTTP access log.

Investigating in Axiom

All three sources feed into Axiom, which we use as the SIEM for the lab. We can search the collected events, follow activity across our cloud services and servers, and test detection ideas against the data.