Security Operations Center
(Mini SIEM) Dashboard
A lightweight, high-performance Security Information and Event Management (SIEM) platform designed to parse structured security logs, detect brute-force attacks via sliding window analytics, enforce IP threat intelligence, and deliver real-time severity alerting.
Core Security Capabilities
Simulating real-world enterprise SOC log monitoring & threat detection workflows.
Structured Log Parsing
Regex-based ingestion engine parsing timestamp, event type, and IP metadata from raw system authentication logs in real time.
Sliding-Window Attack Detection
Automated detection algorithm flagging high-frequency brute-force attempts with dynamic queue-based time windows.
Threat Intelligence & Blacklist
Automatic correlation against static threat intelligence blacklists to catch suspicious malicious actors instantly.
Whitelist Suppression
False-positive reduction logic suppressing alerts for verified internal IP ranges (e.g. 127.0.0.1, 192.168.x.x).
Severity Classification
Categorized alert outputs (CRITICAL, HIGH, MEDIUM, LOW) enabling fast triage for security operations analysts.
RESTful Analytics API
Structured endpoints (/api/logs, /api/alerts, /api/summary) designed for SIEM dashboard consumption & automated reporting.
How the SIEM Pipeline Works
End-to-end data processing workflow from raw logs to actionable alerts.
Log Ingestion
Ingests system logs from structured file formats.
Pattern Analysis
Evaluates sliding window thresholds & threat lists.
Database Storage
Persists verified security alerts into SQLite & JSON.
SOC Visualization
Renders real-time telemetry on the Interactive Dashboard.