Logging & Monitoring

Logging & Monitoring

This section covers centralized logging and security monitoring in the ProxLink homelab using Splunk.

Why Splunk?

Splunk is a platform for collecting, indexing, and searching machine data. In ProxLink it acts as the lab’s SIEM, providing:

  • Centralized log collection from every component in the lab
  • Search and correlation across firewall, DNS, VPN, and host logs
  • Dashboards for visualizing network and security activity
  • Alerts that trigger on suspicious events

Log Sources

SourceComponentWhat is collected
FirewallOPNsenseFirewall rule matches, blocked connections, system events (remote syslog)
DNSTechnitium DNSClient queries, blocked domains
VPNNetBirdPeer connections and access activity
HostsUbuntu Desktop / Server VMsSystem and authentication logs