English | 简体中文
Elkeid HUB is a rule/event processing engine maintained by the Elkeid Team that supports streaming/offline (not yet supported by the community edition) data processing. The original intention is to solve complex data/event processing and external system linkage requirements through standardized rules.
INPUTdata input layer, community edition only supports Kafka.
RULEENGINE/RULESETcore components for data detection/external data linkage/data processing.
OUTPUTdata output layer, community edition only supports Kafka/ES.
SMITH_DSLused to describe the data flow relationship.
- Simple HIDS
- IDS Like Scenarios
- Multiple input and output scenarios
- High Performance
- Very Few Dependencies
- Support Complex Data Processing
- Custom Plugin Support
- Support Stateful Logic Build
- Support External System/Data Linkage
Elkeid Internal Best Practices
- Use Elkeid HUB to process Elkeid HIDS/RASP/Sandbox/etc. raw data, TPS ninety million/s. HUB scheduling instance 4000+
- 99% alarm produce time is less than 0.5s
- Internal Maintenance Rules 2000+
Elkeid HUB Handbook (chinese only)
Elkeid HIDS Rule and Project(Just Example)
(Need to use with Elkeid)
- Does not support cluster mode, only supports single node.
- No front-end support, no data visualization capabilities, no front-end management capabilities.
- Rule/RuleSet/Project Debug capabilities are not supported.
- WorkSpace is not supported, user management is not supported.
- No operation and maintenance management capabilities.