cancel
Showing results for 
Search instead for 
Did you mean: 
ustevens
Staff
Staff
Status: Reviewed

Currently, security events such as logins, invalid passwords etc are stored disparately within the Chorus database and log files. It would be beneficial for these event types to be able to be streamed from Chorus to systems such as Kafka. 
Event types (not exhaustive) are:

  • Logon/logoff
  • Failed logon attempts
  • Password changes
  • Account creation & deletions
  • Account (un)lock & disables
  • Security group changes

The benefit of this would be that the events can be combined with data from surrounding/integrated systems to provide a more complete security picture in SIEM applications to flag security events such as breaches, unauthorised access etc., which would then enable a forensic record of all security events.