Ross ROSS = Recommend OSS · open-source software intelligence for agents

philhagen/sof-elk

Configuration files for the SOF-ELK VM observed · 2026-08-28

github.com/philhagen/sof-elk · Ruby · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

76/100

  • Activity 97
  • Release rhythm 35
  • Longevity 100

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 4264
  • days_rel: n/a
  • days_push: 18
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1753 stars · 304 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

SOF-ELK is a pre-built virtual appliance based on the Elastic stack (Elasticsearch, Logstash, Kibana, Filebeat) tailored for computer forensics and security operations. This repository holds the configuration and support files that power the appliance, enabling ingestion, parsing, and visualization of log and NetFlow data without manual Elastic stack setup.

Use cases

  • analyze network forensic evidence from log files and NetFlow
  • investigate security incidents with pre-built Kibana dashboards
  • ingest and parse multiple log formats without configuring the Elastic stack
  • explore timeline data during digital forensics investigations
  • support SANS FOR572-style network forensics coursework
  • build custom visualizations for security operations analysis

When to choose

  • you need a ready-to-use forensic/security log analysis platform without lengthy Elastic stack setup
  • you are a forensic investigator or SOC analyst analyzing logs, NetFlow, or timeline data
  • you want pre-built dashboards and parsers for common log formats
  • you are following SANS FOR572 or similar network forensics training

When to avoid

  • you need a general-purpose production log management system rather than a forensic analysis appliance
  • you want to run the config files outside the distributed SOF-ELK VM, since no support is provided
  • you need a lightweight tool - the appliance is a full VM with significant resource requirements
  • you require a fully managed or cloud-hosted Elastic deployment

Facets

application · maturity active

search-engine analytics data-visualization logging etl security analytics big-data developer-tools self-hosted elastic-stack logstash kibana elasticsearch filebeat netflow digital-forensics incident-response log-analysis virtual-appliance linux docker vm

1 source

Member repositories

RepositoryRoleHealth v2
philhagen/sof-elkmain76

For agents

markdown · JSON · MCP: product_card(name="philhagen/sof-elk")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem