Rizky Adhytia
Amikom Purwokerto University

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

IMPLEMENTASI SECURITY INFORMATION AND EVENT MANAGEMENT (SIEM) MENGGUNAKAN WAZUH UNTUK DETEKSI DAN ANALISIS INSIDEN KEAMANAN WEB SERVER: IMPLEMENTATION OF SECURITY INFORMATION AND EVENT MANAGEMENT (SIEM) USING WAZUH FOR DETECTION AND ANALYSIS OF WEB SERVER SECURITY INCIDENTS Rizky Adhytia; Taqwa Hariguna
Rabit : Jurnal Teknologi dan Sistem Informasi Univrab Vol 11 No 2 (2026): Juli
Publisher : LPPM Universitas Abdurrab

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.36341/rabit.v11i2.8054

Abstract

The rapid development of web server technology has increased the risk of cyber threats such as brute force and Distributed Denial of Service (DDoS) attacks. This study aims to implement a Security Information and Event Management (SIEM) system using Wazuh to detect and analyze security incidents on a web server in real time. The research method used is experimental, consisting of requirements analysis, system design, implementation, testing, and evaluation. The system is built using a Wazuh Server, a Wazuh Agent installed on an Ubuntu-based web server, and Telegram notification integration for automatic alerts to administrators. Testing was conducted through attack simulations using Hydra for SSH brute force, Slowloris, and DDoS-Ripper for DoS attacks. The results show that the system successfully detected various attacks with Rule ID 5712 and 5763 for SSH brute force, Rule ID 100502 for Slowloris HTTP flood, and Rule ID 100500 and 100501 for DDoS-Ripper. All attacks were successfully detected and reported to Telegram in real time. The Wazuh-based SIEM implementation improves monitoring, detection, and response capabilities for web server security incidents in a centralized manner and provides better security visibility for administrators in handling cyber threats.