- Posted on
- Featured Image
Learn how to turn noisy Linux logs into actionable SIEM events with a lightweight, Bash-first AI enrichment pipeline: stream journald as JSON, classify severity, tags, MITRE IDs with a local Ollama LLM, merge results, and forward via rsyslog/logger. Covers setup on major distros, SSH-focused demo, hardening/perf tips, and next steps to expand sources and automate high-severity triage.