Lightweight MIT-licensed Fluent Bit alternative in Go: tail files, enrich JSON, ship to Kafka/file/HTTP or custom sinks.
-
Updated
Aug 8, 2026 - Go
Lightweight MIT-licensed Fluent Bit alternative in Go: tail files, enrich JSON, ship to Kafka/file/HTTP or custom sinks.
Step-by-step guide and reference implementation for securely forwarding AWS CloudWatch Logs to Splunk Enterprise Free with near-real-time delivery and a conservative ingestion cutoff.
Air Traffic Controller for log-forwarder agents
Pure Go RELP forwarder & listener for syslog-ng — drop-in binaries via program() driver, no librelp required
SSH detection gap remediation — installed rsyslog, enabled ForwardToSyslog on Kali Linux, confirmed auth.log ingestion into Elastic SIEM, and validated end-to-end SSH brute force alerting with 31 alerts fired
Containerized syslog fan-out with WebUI — transparent relay by default (rsyslog engine + Fastify/Vue management)
Detection engineering project focused on Sysmon tuning, noise reduction, and integrating endpoint telemetry into Splunk to improve visibility and alert fidelity.
Automated syslog forwarding deployment for mixed Linux environments including legacy RHEL 5/6 systems
Config-embedded python RELP protocol implementation for syslog-ng
LUnA — the logrok universal agent: one static, dependency-free binary that collects endpoint and OT logs (Windows Event Log, ETW, WMI, files, journald, syslog, Linux audit, macOS, SNMP, Modbus) and forwards them as RFC 5424 syslog over TLS — or natively to Splunk HEC, Sentinel, XSIAM, Kafka, S3, Loki, OTLP. Air-gap ready. Public downloads & docs.
Lab 2 for Cyber Threat Intelligence (CTI) — Integration of MISP with Elastic Stack for IoC ingestion, and deployment of Elastic Agents on Linux and Windows endpoints via Fleet Server for centralized log forwarding.
To associate your repository with the log-forwarding topic, visit your repo's landing page and select "manage topics."