The community SIEM.
We use Axiom as our SIEM, bringing together AWS management events and systemd and audit logs from our on-prem Linux servers.
A place to investigate activity, try out detection ideas and learn from real systems.
Where the data goes
All management events
Linux
All systemd + audit logs
Cloudflare
Sampled analytics
Axiom
SIEM / Search and analysis
AWS management events
All AWS management events are sent to Axiom. These record control-plane activity, such as API calls that create, change or inspect AWS resources.
Linux systemd and audit logs
Our local Linux servers send all their systemd journal and audit logs. The journals contain service and system messages; audit logs record activity captured by the servers’ audit rules.
Cloudflare analytics
Cloudflare sends traffic summaries, sampled HTTP requests and available security events into Axiom through a scheduled analytics collector. These help us investigate web traffic and security activity, but they are not a complete HTTP access log.
Investigating in Axiom
All three sources feed into Axiom, which we use as the SIEM for the lab. We can search the collected events, follow activity across our cloud services and servers, and test detection ideas against the data.