Skip to content

Navigation Menu

Sign in
Sign up

Latest commit

History

927 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

FLASI Logo

FLASI β€” Firewall Log Analytics for Security Insights

The Best Analytics Platform for Firewall Logs

πŸ“š Full Documentation β€’ πŸš€ Installation β€’ πŸ›£οΈ Roadmap

Discord GitHub stars License


🎯 What is FLASI?

Tired of expensive SIEMs that don't understand firewall logs?

FLASI is a full-featured analytics platform that transforms Fortinet (FortiGate, FortiEDR, FortiMail, FortiWeb) and Palo Alto PAN-OS logs into actionable threat intelligence without breaking the bank.

After 10+ years fighting with overpriced SIEMs that treat firewall logs as a leftover checkbox in a datasheet, we built the platform we always needed.

No sampling. No filtering. Full visibility. Full behavioral analysis.

πŸ’° The Problem We Solve

Traditional SIEMs force you to choose:

  • Option A: Log everything β†’ Go bankrupt from licensing costs
  • Option B: Sample/filter logs β†’ Miss threats hiding in the gaps

We chose Option C: Build a platform optimized specifically for high-volume firewall logs using modern, cost-effective tech.

Built by security analysts, for security analysts

✨ Key Features

πŸ” Deep Ingestion

  • Full field parsing - Every field from Fortinet and Palo Alto logs, not just the "important" ones
  • ECS standardization - Translates to Elastic Common Schema
  • Rich enrichment - GeoIP, network community ID, registered domains, threat intel integration

πŸ“Š Unmatched Analytics

  • Purpose-built dashboards for threat hunting (Kibana & Grafana)
  • Behavioral analysis - Detect slow burns, lateral movement, beaconing
  • No other tool (paid or free) has this depth of firewall log analysis

πŸ› οΈ Security Engineer Friendly

  • One-script deployment for Elasticsearch components
  • Pre-configured pipelines for Vector and Elastic Agent
  • Production-ready dashboards on day one
  • No vendor lock-in - swap components as needed

πŸ—οΈ Modular Architecture

Fortinet/Palo Alto β†’ Vector/Elastic Agent β†’ Elasticsearch/Victoria Logs β†’ Kibana/Grafana

Mix and match: Every layer is swappable. Use what works for your environment.

πŸ“– Documentation

All detailed documentation has moved to our dedicated documentation site:

🎨 Dashboard Preview

Dashboard

Navigate seamlessly through traffic, UTM, and event dashboards

🌟 Why FLASI?

Feature Traditional SIEM FLASI
Cost $$$$$+ per GB Free + your infrastructure
Firewall Focus Generic checkbox Purpose-built
Full Parsing "Important fields" Every field extracted
Sampling Required for cost Log everything
Dashboards Generic Threat hunting focused
Setup Time Weeks/months Hours

🀝 Community & Support

Get Help

Support the Project

You're already saving thousands on SIEM costs. Consider giving back:

πŸ—ΊοΈ Supported Platforms

Data Sources

  • βœ… Fortinet FortiGate
  • βœ… Fortinet FortiEDR
  • βœ… Fortinet FortiMail
  • βœ… Fortinet FortiWeb / FortiAppSec
  • βœ… Palo Alto PAN-OS

Ingestion

  • βœ… Vector (recommended)
  • ⚠️ Elastic Agent (deprecated)
  • ⚠️ Logstash (deprecated)

Storage Backends

  • βœ… Victoria Logs (recommended)
  • βœ… Elasticsearch

Visualization

  • βœ… Grafana (recommended)
  • βœ… Kibana

πŸ“œ License

Apache-2.0 license - See LICENSE for details

πŸ‘₯ Authors

  • Logstash pipelines, Elasticsearch config: @hoat23 & @dr4gon123
  • Datasets, Kibana/Grafana dashboards, Vector pipelines, Victoria Logs: @dr4gon123
  • Current maintenance and development: @dr4gon123

About

Fortinet and Palo Alto logs to VictoriaLogs and Elasticsearch

Topics

Resources

Stars

111 stars

Watchers

18 watching

Forks

Releases

Packages

Used by

Contributors

Languages

AltStyle γ«γ‚ˆγ£γ¦ε€‰ζ›γ•γ‚ŒγŸγƒšγƒΌγ‚Έ (->γ‚ͺγƒͺγ‚ΈγƒŠγƒ«) /