Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

run this in docker locally #29

Open
ssi0202 opened this issue Jun 27, 2018 · 4 comments
Open

run this in docker locally #29

ssi0202 opened this issue Jun 27, 2018 · 4 comments

Comments

@ssi0202
Copy link

ssi0202 commented Jun 27, 2018

not knowing alot about aws but is there anything in here that would make it impossible just to run this in docker

@securityclippy
Copy link
Owner

@ssi0202 hey there! Unfortunately there are a TON of dependencies in the current project that make it nearly impossible to run in just docker. It makes use of a bunch of serverless functions as well as the AWS elasticsearch service in order to make setup and maintenance as painless as possible. I've been contemplating what it would take to move these abilities into Kubernetes, but that's probably going to require a full re-write.

Guessing there's no way you can use AWS? :)

@ssi0202
Copy link
Author

ssi0202 commented Jun 29, 2018 via email

@cplmayo
Copy link

cplmayo commented Sep 24, 2018

I am interested in this as well. I am using ELK to collect all of my logs from pfsense and suricata together and want to enrich and alert the events based on Threat Intel and this solution looks pretty amazing for the enrichment part of it. Don't know what the cost would be to run a personal AWS instance of this, $40 - 50 / Month? But if I could run locally it could reduce my cost.

@securityclippy
Copy link
Owner

@cplmayo for the first question, cost in aws, it really depends on how much data you're keeping. If you set ES to prune data older than 14-30 days, $40-$50 is probably pretty accurate.

I've got another project I'm currently dumping most of my time into right now, but when that's done (ish) in a month or two, I'm hoping to port most of this to kubernetes. I'll make sure to drop an update when that happens!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants