Platform Module 04

Syslog Intelligence
Raw Logs → Security Insight

High-performance log collection, AI-powered threat correlation, and automated response — on top of every log in your infrastructure.


1M+
Events/sec
Ingestion capacity per collector node
2s
Detection Latency
From log receipt to threat alert
300+
Threat Rules
Pre-built detection rules, MITRE ATT&CK mapped
90%
Noise Reduction
AI correlation eliminates redundant log alerts

Enterprise log management
at scale

GlideHubAi's syslog module uses a high-performance collection and forwarding engine trusted by enterprise deployments worldwide. We extend it with a modern parsing pipeline, AI-driven analysis layer, and tight integration with the rest of the platform.

Multi-Source Log Collection
  • UDP/TCP Syslog — RFC 3164 (legacy) and RFC 5424 (structured syslog) on ports 514 UDP, 514 TCP, and 6514 TLS.
  • TLS-encrypted transport — RELP (Reliable Event Logging Protocol) with imrelp — guaranteed delivery, no dropped messages even during network disruptions.
  • File monitoring — imfile module monitors log files on disk with inotify for real-time tailing — ideal for application logs that don't emit syslog.
  • Windows Event Log — WinRM-based collection of Windows Security, Application, and System event logs normalized to syslog format.
  • Beats/Logstash — Accept Elastic Beats (Filebeat, Winlogbeat) and Logstash JSON forwarding for hybrid environments.
  • Cloud logs — AWS CloudTrail, Azure Monitor, GCP Cloud Logging ingested via API polling with normalization.
  • Network device syslogs — Cisco, Juniper, Fortinet, Palo Alto log forwarding with vendor-specific message parsers (facility/severity mapped).
Log Parsing & Normalization
  • High-performance field extraction — liblognorm-based parsing engine extracts structured fields from thousands of log formats using RuleBase definitions — no regex overhead at scale.
  • Vendor parsers — Pre-built parsers for Cisco ASA, PIX, IOS; Juniper SRX; Palo Alto PAN-OS; Fortinet FortiOS; Windows Event XML.
  • Custom RuleBases — Define your own liblognorm rules for proprietary application logs using a simple line-annotation syntax.
  • Field enrichment — Automatic enrichment: GeoIP lookup (MaxMind), hostname→asset lookup, WHOIS data for external IPs.
  • ECS normalization — Output normalized to Elastic Common Schema (ECS) fields for compatibility with Elasticsearch/Kibana downstream.
  • CEF / LEEF support — Parse ArcSight CEF and QRadar LEEF formats for SIEM migration or hybrid deployments.
Threat Detection Rules
  • MITRE ATT&CK mapping — 300+ detection rules mapped to MITRE ATT&CK tactics and techniques with severity scoring.
  • Brute force detection — Count-based correlation: X failed auth attempts from same source IP within Y seconds → HIGH severity alert.
  • Privilege escalation — Pattern-match for sudo, su, UAC bypass, and Windows token manipulation events.
  • Data exfiltration signals — Unusual outbound data volumes detected by correlating syslog with netflow data.
  • Anomaly detection — AI baseline learns normal log patterns per host; alerts on deviations (e.g. unusual login hour, first-time access to sensitive file).
  • Threat intelligence feeds — Real-time lookups against AlienVault OTX, Shodan, and custom STIX/TAXII feeds for known-bad IPs and domains.
Automated Response Actions
  • IP blocking — Push firewall deny rules to Cisco ACL, Palo Alto Security Policy, or iptables on detection of malicious source IP.
  • Account disable — AD/LDAP integration to disable compromised accounts automatically when credential abuse detected.
  • Session termination — Kill active SSH/RDP sessions flagged as suspicious via API calls to target systems.
  • Trigger backup — Detected config change in syslog → immediately trigger configuration backup and diff analysis.
  • Ticket creation — Auto-generate security incidents in ServiceNow, Jira, or Freshservice with full log context attached.
  • SOAR integration — Push enriched alerts to Splunk SOAR, Palo Alto XSOAR, or IBM Resilient for advanced orchestration.
Live Log Stream
1,247,382 events/hr
Mar 22 14:23:01 core-fw-01 kernel: [UFW BLOCK] IN=eth0 SRC=185.220.101.47 DST=10.0.0.1 PROTO=TCP DPT=22
Mar 22 14:23:02 auth-srv-02 sshd[4821]: Failed password for root from 185.220.101.47 port 52341
Mar 22 14:23:03 ⚠ ALERT Brute force detected: 47 failed SSH attempts in 60s from 185.220.101.47
Mar 22 14:23:03 ▶ AUTO Blocking IP 185.220.101.47 on core-fw-01 via API
Mar 22 14:23:05 app-web-03 nginx: 192.168.1.42 "GET /api/users HTTP/1.1" 200 4823
Mar 22 14:23:07 db-pgsql-01 LOG: connection received: host=10.0.5.12 port=54321 user=app_user
Mar 22 14:23:09 core-sw-01 %SYS-5-CONFIG_I: Configured from console by admin on vty0 (10.0.1.5)
Mar 22 14:23:09 ◆ WARN Config change detected on core-sw-01 — triggering immediate backup
Log Forwarding Configuration Example
# /etc/logd/99-glidehubai.conf # Forward to GlideHubAi collector via RELP+TLS module(load="omrelp") action( type="omrelp" target="collector.glidehubai.internal" port="2514" tls="on" tls.cacert="/etc/ssl/certs/glide-ca.pem" tls.mycert="/etc/ssl/certs/host.pem" tls.myprivkey="/etc/ssl/private/host.key" queue.type="LinkedList" queue.size="10000" queue.saveOnShutdown="on" action.resumeRetryCount="-1" )

What's included in
GlideHubAi syslog intelligence

Capability AreaFeatureIncludedNotes
CollectionUDP/TCP Syslog (RFC 3164 + RFC 5424)Ports 514, 6514 TLS
CollectionRELP guaranteed deliveryDefault on, no config needed
CollectionFile tailing with inotifyReal-time application log pickup
CollectionWindows Event Log (WinRM)Security, Application, System
CollectionCloud logs (AWS, Azure, GCP)API polling + normalization
ParsingVendor-specific log parsersCisco, Juniper, Palo Alto, Fortinet
ParsingGeoIP + asset enrichmentMaxMind, internal CMDB lookup
DetectionMITRE ATT&CK mapped rules (300+)Pre-built, always updated
DetectionAI anomaly detectionIncluded — no extra tier
DetectionThreat intelligence feed integrationOTX / STIX-TAXII
ResponseAutomated firewall block, account disableNative automation engine
IntegrationTrigger config backup on change logCross-module, same platform
IntegrationUnified network monitoring correlationNo separate stack required
DeploymentSaaS or single-VM on-premisesLow complexity, fast deployment

Every log. Every threat.
One platform.