LOG AGGREGATION · EVENT REVIEW · SECURITY VISIBILITY · SENTINEL ROADMAP
The SIEM Sandbox will become the security event review layer of The Citadel. Its purpose is to collect, organize, and visualize security-relevant activity from Linux logs, SSH events, Fail2Ban activity, and future monitoring sources.
This page currently documents the planned direction for transforming raw authentication and system logs into searchable security intelligence.