Home / Companies / Confluent / Blog / Post Details
Content Deep Dive

Seamless SIEM – Part 2: Anomaly Detection with Machine Learning and ksqlDB

Blog post from Confluent

Post Details
Company
Date Published
Author
Hubert Dulay, Victoria Xia, Wade Waldron
Word Count
1,277
Company Posts That Month
10
Language
English
Hacker News Points
-
Post removed?
No
Summary

Building on the first part of the series, this section delves into processing osquery logs using the Confluent Platform and ksqlDB to detect anomalous behavior with machine learning. By training a Latent Dirichlet Allocation (LDA) model on osquery logs, the system can identify deviations in behavior, categorizing them as GOOD, BAD, or UGLY based on their scores. The GOOD logs, indicating normalcy, are fed back into the model for retraining, while BAD logs, suggesting suspicious activity, and UGLY logs, requiring further analysis, can be routed to security systems for deeper investigation. The architecture uses a combination of batch and streaming pipelines, with a Lambda Architecture approach, to manage model training and real-time log scoring. This setup facilitates the integration of the Confluent Platform, Kafka Connect, and ksqlDB to create a streamlined SIEM pipeline capable of real-time alerting and investigation, laying a foundation for scalable security solutions.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Real-time 10 384 151 53 -26%
Serverless 1 1,091 63 25 +323%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.