{"adoption": {"forks": 304, "observed_at": "2026-08-28T04:05:31.793465+00:00", "stars": 1753}, "canonical_url": "https://ross.abutalabs.com/products/sof-elk", "card": {"archived": false, "artifact_type": "application", "description": "Configuration files for the SOF-ELK VM", "domain": ["security", "analytics", "big-data", "developer-tools"], "enriched": true, "function": ["search-engine", "analytics", "data-visualization", "logging", "etl"], "health_score": 79, "homepage": null, "language": "Ruby", "license": "GPL-3.0", "license_family": "copyleft", "maturity": "active", "member_repos": ["philhagen/sof-elk"], "name": "philhagen/sof-elk", "platform": ["self-hosted"], "pushed_at": "2026-08-15T16:45:47+00:00", "repo": "philhagen/sof-elk", "stars": 1753, "tags": ["elastic-stack", "logstash", "kibana", "elasticsearch", "filebeat", "netflow", "digital-forensics", "incident-response", "log-analysis", "virtual-appliance", "linux", "docker", "vm"], "topics": [], "urls": [], "use_cases": ["analyze network forensic evidence from log files and NetFlow", "investigate security incidents with pre-built Kibana dashboards", "ingest and parse multiple log formats without configuring the Elastic stack", "explore timeline data during digital forensics investigations", "support SANS FOR572-style network forensics coursework", "build custom visualizations for security operations analysis"], "what_it_is": "SOF-ELK is a pre-built virtual appliance based on the Elastic stack (Elasticsearch, Logstash, Kibana, Filebeat) tailored for computer forensics and security operations. This repository holds the configuration and support files that power the appliance, enabling ingestion, parsing, and visualization of log and NetFlow data without manual Elastic stack setup.", "when_to_avoid": ["you need a general-purpose production log management system rather than a forensic analysis appliance", "you want to run the config files outside the distributed SOF-ELK VM, since no support is provided", "you need a lightweight tool - the appliance is a full VM with significant resource requirements", "you require a fully managed or cloud-hosted Elastic deployment"], "when_to_choose": ["you need a ready-to-use forensic/security log analysis platform without lengthy Elastic stack setup", "you are a forensic investigator or SOC analyst analyzing logs, NetFlow, or timeline data", "you want pre-built dashboards and parsers for common log formats", "you are following SANS FOR572 or similar network forensics training"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/sof-elk", "repo": "philhagen/sof-elk", "role": "main", "score": 76}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:05:31.793465+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T03:28:14.633663+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d64179c2a25c73a20fb6474491e5ca34275e2599e91276d73514103a8fe5d84e", "fetched_at": "2026-08-28T04:05:31.793465+00:00", "kind": "readme", "missing": false, "url": "https://github.com/philhagen/sof-elk"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:05:31.793465+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T03:28:14.633663+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d64179c2a25c73a20fb6474491e5ca34275e2599e91276d73514103a8fe5d84e", "fetched_at": "2026-08-28T04:05:31.793465+00:00", "kind": "readme", "missing": false, "url": "https://github.com/philhagen/sof-elk"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T03:28:14.633663+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d64179c2a25c73a20fb6474491e5ca34275e2599e91276d73514103a8fe5d84e", "fetched_at": "2026-08-28T04:05:31.793465+00:00", "kind": "readme", "missing": false, "url": "https://github.com/philhagen/sof-elk"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:05:31.793465+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:05:31.793465+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:05:31.793465+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T03:28:14.633663+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d64179c2a25c73a20fb6474491e5ca34275e2599e91276d73514103a8fe5d84e", "fetched_at": "2026-08-28T04:05:31.793465+00:00", "kind": "readme", "missing": false, "url": "https://github.com/philhagen/sof-elk"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:05:31.793465+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:05:31.793465+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T03:28:14.633663+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d64179c2a25c73a20fb6474491e5ca34275e2599e91276d73514103a8fe5d84e", "fetched_at": "2026-08-28T04:05:31.793465+00:00", "kind": "readme", "missing": false, "url": "https://github.com/philhagen/sof-elk"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:05:31.793465+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:05:31.793465+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:05:31.793465+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T03:28:14.633663+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d64179c2a25c73a20fb6474491e5ca34275e2599e91276d73514103a8fe5d84e", "fetched_at": "2026-08-28T04:05:31.793465+00:00", "kind": "readme", "missing": false, "url": "https://github.com/philhagen/sof-elk"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:05:31.793465+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:05:31.793465+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T03:28:14.633663+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d64179c2a25c73a20fb6474491e5ca34275e2599e91276d73514103a8fe5d84e", "fetched_at": "2026-08-28T04:05:31.793465+00:00", "kind": "readme", "missing": false, "url": "https://github.com/philhagen/sof-elk"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T03:28:14.633663+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d64179c2a25c73a20fb6474491e5ca34275e2599e91276d73514103a8fe5d84e", "fetched_at": "2026-08-28T04:05:31.793465+00:00", "kind": "readme", "missing": false, "url": "https://github.com/philhagen/sof-elk"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T03:28:14.633663+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d64179c2a25c73a20fb6474491e5ca34275e2599e91276d73514103a8fe5d84e", "fetched_at": "2026-08-28T04:05:31.793465+00:00", "kind": "readme", "missing": false, "url": "https://github.com/philhagen/sof-elk"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T03:28:14.633663+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d64179c2a25c73a20fb6474491e5ca34275e2599e91276d73514103a8fe5d84e", "fetched_at": "2026-08-28T04:05:31.793465+00:00", "kind": "readme", "missing": false, "url": "https://github.com/philhagen/sof-elk"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 97, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-02T17:46:02.011165+00:00", "flags": ["no_releases"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 4264, "days_push": 18, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 76, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}