Analysis of SIEM and NIDS Integration for Network Monitoring

Authors

  • Suryayusra Universitas Bina Darma
  • Delfin Christofa Universitas Bina Darma
  • Ilman Zuhri Yadi Universitas Bina Darma
  • Rahmat Novrianda Dasmen Universitas Bina Darma

DOI:

10.33395/sinkron.v10i4.16680

Keywords:

discord, KAMI Index, NIDS, SIEM, Suricata, Wazuh

Abstract

Network security monitoring is generally still carried out manually (dashboard-gazing), creating a time gap between the moment an incident is detected and the moment it is recognised and responded to by the administrator. This condition is aggravated by a Network Intrusion Detection System (NIDS) that works on its own, because its detection logs remain raw and unstructured, making them difficult to manage and analyse. This study proposes the integration of a Suricata-based NIDS with a Wazuh-based Security Information and Event Management (SIEM), on the grounds that Wazuh is able to manage and organise the raw Suricata logs into structured data while correlating them centrally. The integration was carried out by connecting the Suricata sensor to the Wazuh Server, so that the detection logs (eve.json), which were originally in raw JSON format, could be parsed into alerts with rule IDs and levels that are easy to analyse. Testing was conducted through the simulation of five attack scenarios (brute force, LFI, directory brute force, SQL injection, XSS) over 12 days, producing a correlation of 25,414 security logs covering all scenarios. The security readiness measurement using the KAMI Index v5.0 in the Technology Area shows that 5 of 35 criteria (14.3%) are directly fulfilled and 7 criteria (20%) are partially fulfilled. As an added value, all alerts resulting from the integration were forwarded through webhook-based Discord notifications without any delivery failure, shortening the time between a threat being detected and that threat becoming known to the administrator.

GS Cited Analysis

Downloads

Download data is not yet available.

References

Adrian, A. Z. A., Megantara, R. A., & Al Zami, F. (2026). Hybrid Multilayer Architecture Integrating Suricata, Wazuh, and Cyber Threat Intelligence for Drive-by-Download Malvertising Detection. Sinkron: Jurnal Dan Penelitian Teknik Informatika, 10(1), 161–168.

Amami, R., Charfeddine, M., & Masmoudi, S. (2024). Exploration of Open Source SIEM Tools and Deployment of an Appropriate Wazuh-Based Solution for Strengthening Cyberdefense. 2024 10th International Conference on Control, Decision and Information Technologies (CoDIT), 1–7.

Damanik, H. A., & Anggraeni, M. (2024). Sistem Deteksi Intrusi Hybrid dan Mitigasi Kerentanan Infrastruktur Jaringan Menggunakan Teknik Active Response (XDR) Wazuh dan Suricata. Jurnal Pekommas, 9(2), 309–322. https://doi.org/10.56873/jpkm.v9i2.5829

Dasmen, R. N., Kurniawan, F., Komputer, T., & Inggris, S. (2021). Digital Forensik Deleted Cyber Crime Evidence pada Pesan Instan Media Sosial. Techno. COMCom, 20(4), 527–539.

Gede Parama Antara, & Ika Dyah Agustia Rachmawati. (2024). Implementasi dan Analisis Wazuh Sebagai Intrusion Detection System (IDS) dan Platform Monitoring. Jurnal Informasi, Sains Dan Teknologi, 7(2), 290–303. https://doi.org/10.55606/isaintek.v7i2.301

Khusna, T. N., & Sugiantoro, B. (2023). JIPI (Jurnal Ilmiah Penelitian dan Pembelajaran Informatika) Journal homepage: https://jurnal.stkippgritulungagung.ac.id/index.php/jipi. 8(3), 847–856. https://doi.org/10.29100/jipi.v8i3.3720

Krishnan, P., Jain, K., Aldweesh, A., Prabu, P., & Buyya, R. (2023). OpenStackDP: a scalable network security framework for SDN-based OpenStack cloud infrastructure. Journal of Cloud Computing, 12(1), 26.

Lusita, D., Anissa, F., & Andryani, R. (2022). Penerapan Cloud Computing Dalam Aplikasi Panggil Teknisi Berbasis Android Menggunakan Google Cloud Platform. Jurnal Sains Komputer & Informatika (J-SAKTI, 6(2), 1292–1300.

Moiz, S., Majid, A., Basit, A., Ebrahim, M., Abro, A. A., & Naeem, M. (2024). Security and threat detection through cloud-based Wazuh deployment. 2024 IEEE 1st Karachi Section Humanitarian Technology Conference (KHI-HTC), 1–5.

Nandaputra, J. R., Sukarno, P., & Wardana, A. A. (2024). Detection and Prevention System on Computer Network to Handle Distributed Denial-Of-Service (Ddos) Attack in Realtime and Multi-Agent. ACM International Conference Proceeding Series, 237–241. https://doi.org/10.1145/3674558.3674592

Putu, I., Krisna Wiranata, T., Istri, A. A., Paramitha, I., & Satwika, P. (2023). ANALISIS PERBANDINGAN PERFORMA APP ENGINE DAN COMPUTE ENGINE PADA GOOGLE CLOUD PLATFORM DALAM MEMPREDIKSI PENYAKIT MATA DENGAN MODEL CNN. JATI (Jurnal Mahasiswa Teknik Informatika), 7(6), 3968–3977. https://doi.org/10.36040/JATI.V7I6.7976

Sarah Aulia Rahmah. (2023). Efektifitas Penerapan Algoritma Brute Force dan Penyalahgunaannya Dalam Sistem Berbasis Web. Journal of Computers and Digital Business, 2(3), 112–119. https://doi.org/10.56427/JCBD.V2I3.235

Subhan, A., Kunang, Y. N., & Yadi, I. Z. (2023). Analyzing the attack pattern of brute force attack on SSH port. 2023 International Conference on Information Technology and Computing (ICITCOM), 67–72.

Suryantoro, T., Purnomosidi, B. D. P., & Andriyani, W. (2022). The analysis of attacks against port 80 webserver with SIEM Wazuh using detection and OSCAR methods. 2022 5th International Seminar on Research of Information Technology and Intelligent Systems (ISRITI), 1–6.

Suryayusra, & Christofa, D. (2026). Integrasi Wazuh File Integrity Monitoring Dan Suricata Dengan Notifikasi Telegram Untuk Keamanan Jaringan. Jurnal Ilmiah Matrik, 28(1), 49–57. https://doi.org/10.33557/99M23A40

Wulansari, T. T., & Novandi, D. (2022). Evaluation of information security management using the KAMI index framework. 2022 International Conference of Science and Information Technology in Smart Administration (ICSINTESA), 173–177.

Downloads


Crossmark Updates

How to Cite

Suryayusra, Christofa, D., Yadi, I. Z., & Dasmen, R. N. . (2026). Analysis of SIEM and NIDS Integration for Network Monitoring. Sinkron : Jurnal Dan Penelitian Teknik Informatika, 10(4), 2086-2094. https://doi.org/10.33395/sinkron.v10i4.16680