Higher education institutions manage IT infrastructure that stores highly valuable academic, financial, and research data, yet most do not have an adequate Security Operation Center (SOC) due to limited budget and human resources. This condition makes security incidents such as brute force attacks, SQL injection, directory traversal, and automated scanning difficult to detect at an early stage, since log monitoring is still carried out manually and reactively across multiple servers. This study aims to design and implement a lightweight, web-based mini-SIEM (Security Information and Event Management) application built on the Laravel framework, equipped with a custom rule-based detection engine that evaluates NGINX and Laravel log entries using AND/OR pattern matching and threshold/time-window logic. The method used is a system development method consisting of requirement analysis, architecture design, rule engine design, implementation, and testing and evaluation stages. The application was deployed to monitor several servers in real time and its rule engine was evaluated on its ability to classify security events into severity levels (Medium, High, Critical) such as SQL injection attempts, brute force login, directory traversal, and 404 scanning activity. The results show that the developed mini-SIEM is able to centralize multi-server log visibility in a single dashboard and to automatically flag malicious patterns with an appropriate severity classification, including identifying the top source IP addresses and their geographic origin. During the evaluation period, the system processed log entries collected from six monitored servers and generated 7 categories of active alerts (Medium, High, and Critical severity), while the Top IP analysis identified the five most active source addresses, one of which alone accounted for 1,000 recorded attempts. Thus, the implementation of this self-built mini-SIEM is proven to improve security visibility and incident response speed for higher education IT infrastructure without requiring commercial or heavyweight enterprise SIEM solutions.
Copyrights © 2026