cisagov / LME
- среда, 1 ноября 2023 г. в 00:00:08
Logging Made Easy (LME) is a free and open logging and protective monitoring solution serving all organizations.
Initially created by NCSC and now maintained by CISA, Logging Made Easy is a self-install tutorial for small organizations to gain a basic level of centralized security logging for Windows clients and provide functionality to detect attacks. It's the coming together of multiple free and open software platforms, where LME helps the reader integrate them together to produce an end-to-end logging capability. We also provide some pre-made configuration files and scripts, although there is the option to do it on your own.
Logging Made Easy can:
LME is currently still early in development. The current release is version 1.0
If you have an existing install of the LME Alpha (v0.5 or older) some manual intervention will be required in order to upgrade to the latest version, please see Upgrading for further information.
This is not a professional tool, and should not be used as a SIEM.
LME is a 'homebrew' way of gathering logs and querying for attacks.
We have done the hard work to make things simple. We will tell you what to download, which configurations to use and have created convenient scripts to auto-configure wherever possible.
The current architecture is based upon Windows Clients, Microsoft Sysmon, Windows Event Forwarding and the ELK stack.
We are not able to comment on or troubleshoot individual installations. If you believe you have have found an issue with the LME code or documentation please submit a GitHub issue. If you have a question about your installation, please visit GitHub Discussions to see if your issue has been addressed before.
From single IT administrators with a handful of devices in their network to larger organizations.
LME is for you if:
If any, or all, of these criteria fit, then LME is a step in the right direction for you.
LME could also be useful for:
The LME architecture consists of 3 groups of computers, as summarized in the following diagram:
Figure 1: The 3 primary groups of computers in the LME architecture, their descriptions and the operating systems / software run by each.