Analysis of SIEM and NIDS Integration for Network Monitoring
DOI:
10.33395/sinkron.v10i4.16680Keywords:
discord, KAMI Index, NIDS, SIEM, Suricata, WazuhAbstract
Network security monitoring is generally still carried out manually (dashboard-gazing), creating a time gap between the moment an incident is detected and the moment it is recognised and responded to by the administrator. This condition is aggravated by a Network Intrusion Detection System (NIDS) that works on its own, because its detection logs remain raw and unstructured, making them difficult to manage and analyse. This study proposes the integration of a Suricata-based NIDS with a Wazuh-based Security Information and Event Management (SIEM), on the grounds that Wazuh is able to manage and organise the raw Suricata logs into structured data while correlating them centrally. The integration was carried out by connecting the Suricata sensor to the Wazuh Server, so that the detection logs (eve.json), which were originally in raw JSON format, could be parsed into alerts with rule IDs and levels that are easy to analyse. Testing was conducted through the simulation of five attack scenarios (brute force, LFI, directory brute force, SQL injection, XSS) over 12 days, producing a correlation of 25,414 security logs covering all scenarios. The security readiness measurement using the KAMI Index v5.0 in the Technology Area shows that 5 of 35 criteria (14.3%) are directly fulfilled and 7 criteria (20%) are partially fulfilled. As an added value, all alerts resulting from the integration were forwarded through webhook-based Discord notifications without any delivery failure, shortening the time between a threat being detected and that threat becoming known to the administrator.
Downloads
References
Adrian, A. Z. A., Megantara, R. A., & Al Zami, F. (2026). Hybrid Multilayer Architecture Integrating Suricata, Wazuh, and Cyber Threat Intelligence for Drive-by-Download Malvertising Detection. Sinkron: Jurnal Dan Penelitian Teknik Informatika, 10(1), 161–168.
Amami, R., Charfeddine, M., & Masmoudi, S. (2024). Exploration of Open Source SIEM Tools and Deployment of an Appropriate Wazuh-Based Solution for Strengthening Cyberdefense. 2024 10th International Conference on Control, Decision and Information Technologies (CoDIT), 1–7.
Damanik, H. A., & Anggraeni, M. (2024). Sistem Deteksi Intrusi Hybrid dan Mitigasi Kerentanan Infrastruktur Jaringan Menggunakan Teknik Active Response (XDR) Wazuh dan Suricata. Jurnal Pekommas, 9(2), 309–322. https://doi.org/10.56873/jpkm.v9i2.5829
Dasmen, R. N., Kurniawan, F., Komputer, T., & Inggris, S. (2021). Digital Forensik Deleted Cyber Crime Evidence pada Pesan Instan Media Sosial. Techno. COMCom, 20(4), 527–539.
Gede Parama Antara, & Ika Dyah Agustia Rachmawati. (2024). Implementasi dan Analisis Wazuh Sebagai Intrusion Detection System (IDS) dan Platform Monitoring. Jurnal Informasi, Sains Dan Teknologi, 7(2), 290–303. https://doi.org/10.55606/isaintek.v7i2.301
Khusna, T. N., & Sugiantoro, B. (2023). JIPI (Jurnal Ilmiah Penelitian dan Pembelajaran Informatika) Journal homepage: https://jurnal.stkippgritulungagung.ac.id/index.php/jipi. 8(3), 847–856. https://doi.org/10.29100/jipi.v8i3.3720
Krishnan, P., Jain, K., Aldweesh, A., Prabu, P., & Buyya, R. (2023). OpenStackDP: a scalable network security framework for SDN-based OpenStack cloud infrastructure. Journal of Cloud Computing, 12(1), 26.
Lusita, D., Anissa, F., & Andryani, R. (2022). Penerapan Cloud Computing Dalam Aplikasi Panggil Teknisi Berbasis Android Menggunakan Google Cloud Platform. Jurnal Sains Komputer & Informatika (J-SAKTI, 6(2), 1292–1300.
Moiz, S., Majid, A., Basit, A., Ebrahim, M., Abro, A. A., & Naeem, M. (2024). Security and threat detection through cloud-based Wazuh deployment. 2024 IEEE 1st Karachi Section Humanitarian Technology Conference (KHI-HTC), 1–5.
Nandaputra, J. R., Sukarno, P., & Wardana, A. A. (2024). Detection and Prevention System on Computer Network to Handle Distributed Denial-Of-Service (Ddos) Attack in Realtime and Multi-Agent. ACM International Conference Proceeding Series, 237–241. https://doi.org/10.1145/3674558.3674592
Putu, I., Krisna Wiranata, T., Istri, A. A., Paramitha, I., & Satwika, P. (2023). ANALISIS PERBANDINGAN PERFORMA APP ENGINE DAN COMPUTE ENGINE PADA GOOGLE CLOUD PLATFORM DALAM MEMPREDIKSI PENYAKIT MATA DENGAN MODEL CNN. JATI (Jurnal Mahasiswa Teknik Informatika), 7(6), 3968–3977. https://doi.org/10.36040/JATI.V7I6.7976
Sarah Aulia Rahmah. (2023). Efektifitas Penerapan Algoritma Brute Force dan Penyalahgunaannya Dalam Sistem Berbasis Web. Journal of Computers and Digital Business, 2(3), 112–119. https://doi.org/10.56427/JCBD.V2I3.235
Subhan, A., Kunang, Y. N., & Yadi, I. Z. (2023). Analyzing the attack pattern of brute force attack on SSH port. 2023 International Conference on Information Technology and Computing (ICITCOM), 67–72.
Suryantoro, T., Purnomosidi, B. D. P., & Andriyani, W. (2022). The analysis of attacks against port 80 webserver with SIEM Wazuh using detection and OSCAR methods. 2022 5th International Seminar on Research of Information Technology and Intelligent Systems (ISRITI), 1–6.
Suryayusra, & Christofa, D. (2026). Integrasi Wazuh File Integrity Monitoring Dan Suricata Dengan Notifikasi Telegram Untuk Keamanan Jaringan. Jurnal Ilmiah Matrik, 28(1), 49–57. https://doi.org/10.33557/99M23A40
Wulansari, T. T., & Novandi, D. (2022). Evaluation of information security management using the KAMI index framework. 2022 International Conference of Science and Information Technology in Smart Administration (ICSINTESA), 173–177.
Downloads
How to Cite
Issue
Section
License
Copyright (c) 2026 Suryayusra, Delfin Christofa, Ilman Zuhri Yadi, Rahmat Novrianda Dasmen

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.






















Moraref
PKP Index
Indonesia OneSearch
OCLC Worldcat
Index Copernicus
Scilit
