How we built a network security monitoring system for an ISP: Zeek, Suricata, OpenSearch, and ClickHouse
Summary
This article explains how to build a network security monitoring stack for an ISP using Zeek, Suricata, Vector, Redis, OpenSearch, ClickHouse, Python, Telegram, and Cisco ACLs. It walks through the architecture, data flow, parsing logic, log handling, and detection logic for SSH attacks, suspicious traffic, and alerting. It also compares Zeek and Suricata, then shows how to scale Zeek with PF_RING and tune the pipeline for real-time analysis. The piece finishes with practical details on IP reputation handling, protected lists, dashboards, and watchdog automation.
Classifications
industries
No industries detected
applications
Anti Piracy
AskAI Classifications
Labels
SaaS
API Products
Data Providers