dataShark is a Security & Network Event Analytics Framework built on Apache Spark that enables security researchers, big data analysts and operations teams to carry out the below tasks with minimal effort:
- Data ingest from various sources such as file system, Syslog, Kafka.
- Write custom map / reduce and ML algorithms that operate on ingested data using abstracted Apache Spark functionality.
- The output of the above operations can be sent to destinations such as syslog, elasticsearch and can also be persisted in the file system or HDFS.
Completely built on Python with a modular framework, helping user develop their own input and output plugins with minimal code required.
Current open source use case helps detect basic bot activity from raw apache access logs. This can help organisations quickly flag attacks without having to invest in other proprietary solutions.
Nominated in the "Best Security Product of the year 2016" at DSCI.
Show less