philhagen/sof-elk
Configuration files for the SOF-ELK VM observed · 2026-08-28
Health v2 · maintenance only
76/100
- Activity 97
- Release rhythm 35
- Longevity 100
Flags: no_releases
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 4264
- days_rel: n/a
- days_push: 18
- n_releases_24m: 0
Adoption not part of the score
1753 stars · 304 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
SOF-ELK is a pre-built virtual appliance based on the Elastic stack (Elasticsearch, Logstash, Kibana, Filebeat) tailored for computer forensics and security operations. This repository holds the configuration and support files that power the appliance, enabling ingestion, parsing, and visualization of log and NetFlow data without manual Elastic stack setup.
Use cases
- analyze network forensic evidence from log files and NetFlow
- investigate security incidents with pre-built Kibana dashboards
- ingest and parse multiple log formats without configuring the Elastic stack
- explore timeline data during digital forensics investigations
- support SANS FOR572-style network forensics coursework
- build custom visualizations for security operations analysis
When to choose
- you need a ready-to-use forensic/security log analysis platform without lengthy Elastic stack setup
- you are a forensic investigator or SOC analyst analyzing logs, NetFlow, or timeline data
- you want pre-built dashboards and parsers for common log formats
- you are following SANS FOR572 or similar network forensics training
When to avoid
- you need a general-purpose production log management system rather than a forensic analysis appliance
- you want to run the config files outside the distributed SOF-ELK VM, since no support is provided
- you need a lightweight tool - the appliance is a full VM with significant resource requirements
- you require a fully managed or cloud-hosted Elastic deployment
Facets
application · maturity active
search-engine analytics data-visualization logging etl security analytics big-data developer-tools self-hosted elastic-stack logstash kibana elasticsearch filebeat netflow digital-forensics incident-response log-analysis virtual-appliance linux docker vm
1 source
- readme: https://github.com/philhagen/sof-elk · fetched 2026-08-28 · d64179c2a25c
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| philhagen/sof-elk | main | 76 |
For agents
markdown · JSON · MCP: product_card(name="philhagen/sof-elk")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem