Exhibit BSecurity monitoring lab
Two small machines, one log pipeline, and the numbers it produced
In plain English: I built a small version of a company’s security monitoring center at home. It collects records of what every device does and flags anything suspicious, so I can test tools before I recommend them to clients.
- 304,708
- events in 24 hours, one index
- 5
- log sources: firewall, DNS, proxy, containers, host agents
- ~3,700
- host-based detection alerts over 7 days
- 2
- Proxmox VE nodes, deliberately unclustered
Why it exists
Before I recommend SIEM, host-based detection or monitoring tooling to a Cyntraix client, I run it here. Scheduled searches produce a daily digest and a critical-event watch under a search-only service account that can read one index and nothing else.
What it caught
A VPN container that had never worked, crash-looping more than 12,000 times and writing about 361 GB to disk. It is gone now, and so is its agent.