I am studying for my Network+ and my Sec+ hoping to shadow our Cyber Sec guy at work.
I want to set up a SIEM on my home network so I can be used to it's operations and how it works by the time I start messing with Pentesting stuff. Then I'm going to use it to try and track myself when I pentest myself.
I was looking into Graylog or Security Onion since they seem to have decent documentation (and I can find videos on how to set them up which is nice).
I was recommended building my own ELK stack and doing everything manually for maximum learning potential. Which I understand why this is a good idea, but I think I'd rather be as close to "baby's first SIEM" as possible or at least have a robust how-to guide.
What do you suggest?
Are you using LLMs as search engines?
Bold.
I use Gemma, LLama 3.2, and Deepseek to either fix formatting, summarize documentation to give me commands for Linux software, and write simple code structure for me to refine into working code.
Sure it takes longer to generate than a cloud compute would, but
privacy obviously. I know you dismissed it but that's really the biggest reason anyone will have.
this feels better environmentally. I actually don't know if that's true, but it objectively touches less computers for such simple tasks. It would be wasteful of infrastructure to do it over the web.
it's just cooler to have a conversation with my computer. I've learned a lot about how the whole process works and that's more valuable to me as a non dev than just getting the end results.