# philhagen/sof-elk

Configuration files for the SOF-ELK VM

Repository: https://github.com/philhagen/sof-elk
Canonical: https://ross.abutalabs.com/products/sof-elk
Language: Ruby
License: GPL-3.0
License Family: copyleft
Last push: 2026-08-15T16:45:47+00:00

## Health v2 (maintenance only)
Score: 76/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 97, release rhythm 35, longevity 100
- inputs: {"age_days": 4264, "days_push": 18, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1753, forks 304 (observed 2026-08-28T04:05:31.793465+00:00)

## What it is
SOF-ELK is a pre-built virtual appliance based on the Elastic stack (Elasticsearch, Logstash, Kibana, Filebeat) tailored for computer forensics and security operations. This repository holds the configuration and support files that power the appliance, enabling ingestion, parsing, and visualization of log and NetFlow data without manual Elastic stack setup.

## Use cases
- analyze network forensic evidence from log files and NetFlow
- investigate security incidents with pre-built Kibana dashboards
- ingest and parse multiple log formats without configuring the Elastic stack
- explore timeline data during digital forensics investigations
- support SANS FOR572-style network forensics coursework
- build custom visualizations for security operations analysis

## When to choose
- you need a ready-to-use forensic/security log analysis platform without lengthy Elastic stack setup
- you are a forensic investigator or SOC analyst analyzing logs, NetFlow, or timeline data
- you want pre-built dashboards and parsers for common log formats
- you are following SANS FOR572 or similar network forensics training

## When to avoid
- you need a general-purpose production log management system rather than a forensic analysis appliance
- you want to run the config files outside the distributed SOF-ELK VM, since no support is provided
- you need a lightweight tool - the appliance is a full VM with significant resource requirements
- you require a fully managed or cloud-hosted Elastic deployment

## Facets
- artifact type: application
- maturity: active
- function: search-engine, analytics, data-visualization, logging, etl
- domain: security, analytics, big-data, developer-tools
- platform: self-hosted
- tags: elastic-stack, logstash, kibana, elasticsearch, filebeat, netflow, digital-forensics, incident-response, log-analysis, virtual-appliance, linux, docker, vm

## Member repositories
- philhagen/sof-elk (main) score 76

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:31.793465+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:28:14.633663+00:00, confidence not recorded.
  - readme: https://github.com/philhagen/sof-elk (fetched 2026-08-28T04:05:31.793465+00:00, sha d64179c2a25c)
- Data as of 2026-08-30T08:39:29.467469+00:00.
