# دليل نشر نظام SIEM على غيمة ## استخدام Block Storage للسجلات --- ## نظرة عامة على البنية ``` ┌─────────────────────────────────────────────────────────────┐ │ غيمة Cloud │ ├─────────────────────────────────────────────────────────────┤ │ ┌─────────────┐ ┌─────────────┐ ┌─────────────┐ │ │ │ Nginx │ │ App │ │ Auth │ │ │ │ Logs │ │ Logs │ │ Logs │ │ │ └──────┬──────┘ └──────┬──────┘ └──────┬──────┘ │ │ │ │ │ │ │ └────────────────┼────────────────┘ │ │ ▼ │ │ ┌───────────────────────┐ │ │ │ Block Storage │ │ │ │ (السجلات المركزية) │ │ │ └───────────┬───────────┘ │ │ │ │ │ ▼ │ │ ┌───────────────────────┐ │ │ │ SIEM Container │ │ │ │ - log_analyzer.py │ │ │ │ - Dashboard │ │ │ └───────────────────────┘ │ └─────────────────────────────────────────────────────────────┘ ``` --- ## الخطوة 1: إنشاء Block Storage على غيمة ### من لوحة تحكم غيمة: 1. اذهب إلى **التخزين** → **Block Storage** 2. اضغط **إنشاء Volume جديد** 3. الإعدادات: - **الاسم**: `siem-logs` - **الحجم**: 50GB (أو حسب الحاجة) - **المنطقة**: نفس منطقة التطبيق - **النوع**: SSD (للأداء العالي) ### أو باستخدام CLI: ```bash # تثبيت Ghaymah CLI npm install -g ghaymah-cli # تسجيل الدخول ghaymah login # إنشاء Block Storage ghaymah storage create \ --name siem-logs \ --size 50 \ --type ssd \ --region me-riyadh-1 ``` --- ## الخطوة 2: ربط Block Storage بالتطبيق ### في ملف docker-compose.yml: ```yaml version: '3.8' services: siem: build: . container_name: siem-analyzer volumes: # ربط Block Storage - /mnt/siem-logs:/var/log/siem # ربط سجلات التطبيقات - nginx-logs:/var/log/nginx:ro - app-logs:/var/log/app:ro - auth-logs:/var/log/auth:ro ports: - "8080:8080" environment: - LOG_PATH=/var/log/siem - RETENTION_DAYS=90 restart: always dashboard: build: ./dashboard container_name: siem-dashboard ports: - "3000:80" depends_on: - siem restart: always volumes: nginx-logs: external: true app-logs: external: true auth-logs: external: true ``` ### في Kubernetes (إذا كنت تستخدمه): ```yaml apiVersion: v1 kind: PersistentVolumeClaim metadata: name: siem-logs-pvc spec: accessModes: - ReadWriteOnce resources: requests: storage: 50Gi storageClassName: ghaymah-block-storage --- apiVersion: apps/v1 kind: Deployment metadata: name: siem-analyzer spec: replicas: 1 selector: matchLabels: app: siem template: metadata: labels: app: siem spec: containers: - name: siem image: siem-analyzer:latest volumeMounts: - name: logs-storage mountPath: /var/log/siem - name: nginx-logs mountPath: /var/log/nginx readOnly: true volumes: - name: logs-storage persistentVolumeClaim: claimName: siem-logs-pvc - name: nginx-logs hostPath: path: /var/log/nginx ``` --- ## الخطوة 3: إعداد جمع السجلات ### تكوين Nginx لإرسال السجلات: ```nginx # /etc/nginx/nginx.conf http { # تنسيق السجلات للـ SIEM log_format siem_format '$remote_addr - $remote_user [$time_local] ' '"$request" $status $body_bytes_sent ' '"$http_referer" "$http_user_agent" ' '$request_time $upstream_response_time'; access_log /var/log/nginx/access.log siem_format; error_log /var/log/nginx/error.log warn; } ``` ### تكوين التطبيق لإرسال السجلات: ```javascript // Node.js - Winston Logger const winston = require('winston'); const logger = winston.createLogger({ format: winston.format.combine( winston.format.timestamp(), winston.format.json() ), transports: [ new winston.transports.File({ filename: '/var/log/app/application.log', maxsize: 100 * 1024 * 1024, // 100MB maxFiles: 10 }) ] }); // تسجيل مع IP app.use((req, res, next) => { logger.info({ ip: req.ip, method: req.method, path: req.path, userAgent: req.get('User-Agent') }); next(); }); ``` --- ## الخطوة 4: Dockerfile للنظام ```dockerfile # Dockerfile FROM python:3.11-slim WORKDIR /app # تثبيت التبعيات COPY requirements.txt . RUN pip install --no-cache-dir -r requirements.txt # نسخ الكود COPY log_analyzer.py . COPY dashboard/ ./dashboard/ # إنشاء مجلدات السجلات RUN mkdir -p /var/log/siem /var/log/nginx /var/log/app /var/log/auth # تشغيل المحلل CMD ["python", "log_analyzer.py", "--daemon"] ``` ```txt # requirements.txt schedule==1.2.0 flask==3.0.0 redis==5.0.0 ``` --- ## الخطوة 5: النشر على غيمة ### باستخدام Git (النشر التلقائي): ```bash # 1. إنشاء مشروع على غيمة ghaymah project create siem-system # 2. ربط Git git remote add ghaymah https://git.ghaymah.systems/username/siem-system.git # 3. النشر git push ghaymah main ``` ### أو باستخدام Docker: ```bash # 1. بناء الصورة docker build -t siem-analyzer:latest . # 2. رفع الصورة لـ Ghaymah Registry docker tag siem-analyzer:latest registry.ghaymah.systems/username/siem-analyzer:latest docker push registry.ghaymah.systems/username/siem-analyzer:latest # 3. النشر ghaymah deploy --image registry.ghaymah.systems/username/siem-analyzer:latest ``` --- ## الخطوة 6: إعداد التنبيهات ### تكوين Webhook للتنبيهات: ```python # في log_analyzer.py - إضافة إرسال التنبيهات import requests def send_alert(alert): """إرسال تنبيه عبر Webhook""" webhook_url = os.environ.get('ALERT_WEBHOOK_URL') if not webhook_url: return payload = { "text": f"🚨 تنبيه أمني: {alert['description']}", "severity": alert['severity'], "ip": alert['source_ip'], "timestamp": alert['timestamp'] } try: requests.post(webhook_url, json=payload, timeout=5) except Exception as e: print(f"فشل إرسال التنبيه: {e}") ``` ### متغيرات البيئة المطلوبة: ```bash # في لوحة تحكم غيمة → إعدادات التطبيق → متغيرات البيئة ALERT_WEBHOOK_URL=https://hooks.slack.com/services/xxx/yyy/zzz LOG_RETENTION_DAYS=90 ANALYSIS_INTERVAL=300 # كل 5 دقائق REDIS_URL=redis://redis:6379 ``` --- ## الخطوة 7: إعداد النسخ الاحتياطي ### تفعيل النسخ الاحتياطي التلقائي: ```bash # من CLI ghaymah storage backup enable \ --volume siem-logs \ --schedule daily \ --retention 30 ``` ### أو من لوحة التحكم: 1. اذهب إلى **التخزين** → **siem-logs** 2. اضغط **النسخ الاحتياطي** 3. فعّل **النسخ التلقائي** 4. اختر **يومي** مع الاحتفاظ لـ 30 يوم --- ## الخطوة 8: المراقبة والصيانة ### مراقبة استخدام التخزين: ```bash # فحص استخدام Block Storage ghaymah storage stats siem-logs # تنظيف السجلات القديمة (أكثر من 90 يوم) find /var/log/siem -type f -mtime +90 -delete ``` ### Cron Job للتنظيف التلقائي: ```bash # إضافة في crontab 0 2 * * * find /var/log/siem -type f -mtime +90 -delete 0 3 * * * python /app/log_analyzer.py --analyze --export ``` --- ## ملخص الأوامر ```bash # إنشاء المشروع ghaymah project create siem-system # إنشاء Block Storage ghaymah storage create --name siem-logs --size 50 # ربط التخزين ghaymah storage attach siem-logs --to siem-system # النشر git push ghaymah main # مراقبة السجلات ghaymah logs siem-system --follow # فحص الحالة ghaymah status siem-system ``` --- ## روابط مفيدة - [وثائق غيمة - Block Storage](https://docs.ghaymah.systems/storage) - [وثائق غيمة - النشر](https://docs.ghaymah.systems/deploy) - [أمثلة على GitHub](https://github.com/ghaymah/examples)