Security Event Pipeline

Primary source needed

CERN’s audit account confirms ingestion of Google Workspace, Azure and network logs, but does not identify the current storage, streaming or analytics products.

This node retains the central security-event pipeline as a research lead without asserting an Elastic/Kafka stack or additional unverified log sources.


Topology