Download the PHP package cboxdk/laravel-siem without Composer
On this page you can find all versions of the php package cboxdk/laravel-siem. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download cboxdk/laravel-siem
More information about cboxdk/laravel-siem
Files in cboxdk/laravel-siem
Package laravel-siem
Short Description The SIEM log-streaming delivery engine for Laravel — a durable transactional outbox, queued batched delivery with retry/backoff/dead-letter/circuit-breaker, SSRF-guarded HTTP egress, encrypted destination secrets, and PII redaction, on top of the framework-agnostic cboxdk/siem core.
License MIT
Homepage https://github.com/cboxdk/laravel-siem
Informations about the package laravel-siem
Cbox SIEM for Laravel
The SIEM log-streaming delivery engine for Laravel: a durable transactional outbox, queued batched delivery with retry, dead-letter, and a per-stream circuit breaker, SSRF-guarded HTTP egress, encrypted destination secrets, and per-field PII redaction — shipping normalized security events to Splunk HEC, Elastic (ECS), Graylog (GELF), ArcSight/syslog (CEF), or any HTTP JSON collector.
This package is the Laravel wrapper over the framework-agnostic
cboxdk/siem core. The core owns the event model
and the formatters (the shape of the data); this package owns delivery (the
network, the durability, the secrets). An audit binding in
cboxdk/laravel-id consumes this layer to
stream a tamper-evident audit trail — that binding is a separate package.
Installation
The service provider is auto-discovered. Destination secrets use Laravel's
encrypter, so an APP_KEY is required (every Laravel app has one).
At a glance
What it guarantees
- Deny-by-default — no enabled stream, nothing delivered.
- At-least-once, unordered — the outbox row commits in your transaction; a rolled-back caller leaves no orphan. Duplicates are possible; dedup by event id.
- Never blocks the request — all delivery is queued.
- Bounded everything — triple-bounded batches (records/bytes/age), bounded exponential backoff with jitter, a hard retry cap into a dead-letter, a bounded outbox with an explicit backpressure policy, and a per-stream circuit breaker.
- Safe egress — SSRF-guarded and DNS-pinned, TLS verification always on, secrets encrypted at rest and scrubbed from logs, PII redacted before formatting.
Destinations
| Destination | SIEM | Framing |
|---|---|---|
splunk_hec |
Splunk HEC | NDJSON to the collector event endpoint, Authorization: Splunk <token> |
elastic_ecs |
Elastic / Kibana | ECS JSON documents (NDJSON) |
graylog_gelf |
Graylog | GELF 1.1 over HTTP (never UDP) |
cef_http |
ArcSight / syslog | CEF lines over HTTP |
generic_json |
any HTTP collector | neutral single-line JSON |
Testing
Compose Cbox\LaravelSiem\Testing\InteractsWithLogStreams into your TestCase to
run the whole pipeline in memory: fakeStreamSink() binds an in-memory
FakeStreamSink, createLogStream(...) registers through the real registry, and
pumpStream($id) runs a delivery cycle synchronously. FakeHttpTransport programs
the HTTP fake for testing the real HttpStreamSink.
Requirements
- PHP 8.4+
- Laravel 12.x or 13.x
- A queue connection, a database, and an
APP_KEY.
Documentation
Full documentation lives in docs/.
The event core
The normalized SiemEvent, the formatters, and their escaping/threat model are
provided by cboxdk/siem. This package claims
only the Laravel delivery layer.
Credits
License
The MIT License (MIT). See LICENSE.md.
All versions of laravel-siem with dependencies
cboxdk/siem Version ^0.1
cboxdk/laravel-ssrf Version ^1.0
illuminate/bus Version ^12.0 || ^13.0
illuminate/contracts Version ^12.0 || ^13.0
illuminate/database Version ^12.0 || ^13.0
illuminate/http Version ^12.0 || ^13.0
illuminate/queue Version ^12.0 || ^13.0
illuminate/support Version ^12.0 || ^13.0