Every system produces independent logs. This makes monitoring logs difficult if not done centrally. The research objective is to monitor and evaluate network security using open source-based Security Information and Event Management (SIEM). The research methods include literature studies, SIEM review, observation at the Data and Information System Center (PDSI), simulation of Open Source SIEM implementation by combining devices in real and GNS3 simulation networks, SIEM deployment using Docker, and the final stage of SIEM application evaluation. The implemented SIEM is able to fulfill 84% of the initial requirements. SIEM integrated with Pfsense firewall and Suricata-Intrusion Prevention System (IPS). Monitoring and evaluation features such as detection and alerting, analysis and investigation, compliance and audit, integration and interoperability, monitoring and reporting, support, and maintenance are important parts of SIEM.
Copyrights © 2023