How we built a network security monitoring system for an ISP: Zeek, Suricata, OpenSearch, and ClickHouse

General News

Summary

This article explains how to build a network security monitoring stack for an ISP using Zeek, Suricata, Vector, Redis, OpenSearch, ClickHouse, Python, Telegram, and Cisco ACLs. It walks through the architecture, data flow, parsing logic, log handling, and detection logic for SSH attacks, suspicious traffic, and alerting. It also compares Zeek and Suricata, then shows how to scale Zeek with PF_RING and tune the pipeline for real-time analysis. The piece finishes with practical details on IP reputation handling, protected lists, dashboards, and watchdog automation.

Classifications

industries
No industries detected
applications
Anti Piracy

AskAI Classifications

Labels
SaaS API Products Data Providers

Linked Companies

MaxMind
$1M to $5M
Cisco
$1B+
Telegram Messenger
$1M to $5M
AbuseIPDB
$1M to $5M