One of the big questions we get when we talk about monitor security metrics is, “How can we collect metrics from multiple services at zero cost?”

You might be tempted to say that it’s not possible, but there is a way. The open-source way.

You could argue that monitoring isn’t at zero cost if some part of the project includes engineer hours to build and maintain the project, and that’s fair.

Also, native services such as cloudtrail, vpcflow logs, and others have a cost associated with them.

However, the combination of:

  • an open-source search engine like ELK
  • open-source software for conformity checks like…

Martin Petracca

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store