@strandjs use it for server and app event analysis. Flexible tokenization logs/data. Powerful rules engine. Woodles for custom data gathering (external cloud providers, tooling, etc.) and integrations (forward events to external apps based upon rules) provides endless possibilities
Me: You gotta patch this public sftp box
Dir of Ops: My guys don’t know how. Sounds like project. Expect 6+ months
Me: It’s CentOS w/ OpenSSH
DoO: Oh, then we need a senior admin. Will take even longer.
Me: Run yum update
DoO: Can’t. We don’t have any tooling or docs
Me: ...
Thx to @SecInnovation for running CMD+CTRL Cyber Range @BASConf. Learned a lot and had great fun. Coming in first and winning an Amazon gift card was nice, too!