{"repo":"clicksiem/clickdetect","free":true,"listed":false,"github":"https://github.com/clicksiem/clickdetect","clone":"git clone https://github.com/clicksiem/clickdetect.git","description":"ClickDetect is a vendor-agnostic alerting framework for threshold-based detection. It works with ClickHouse, OpenSearch/Elasticsearch, VictoriaLogs, PostgreSQL, DuckDB or any custom data source through a flexible integration layer.","language":"Python","stars":52,"topics":["alerting","alerting-system","clickhouse","detection-engine","engine","loki","postgresql","siem","wazuh"],"license":"MIT","category":"databases-storage","readme_excerpt":"Made in :brazil: --- Clickdetect ClickDetect is a vendor-agnostic alerting framework for threshold-based detection. It have a flexible integration system for datasource and webhooks to easly integrate your platform. Follow the documentation: https://clickdetect.souzo.me Core Concepts This is the core concepts for clickdetect. - Runner.yml: The file where you configure everything - Detector: Component that runs rules based on thresholds - Rule: File with structured format to define datasource analysis - Datasource: Where rule queries are executed, like a database or another SIEM engine - Webhooks: Where alerts are sent - Plugin: Script that can intercept Clickdetect actions like on rule triggered Supported Integrations These are the active integrations, but they are not limited to them. Datasources - Clickhouse - Loki - VictoriaLogs - PostgreSQL - Elastic - Opensearch - Opensearch PPL - Databricks - Duckdb Webhooks - Generic - DFIR Iris - Forgejo - Email - Microsoft Teams - Slack - Telegram - Discord - TheHive - Opsgenie - AlertManager Plugins - clickagentic: LLM AI Agent that analyzes your alerts Quick Start Start by creating a runner.yml file — see the full reference in the documentation. uv Follow uv installation in https://docs.astral.sh/uv Docker/Podman Local GitHub Packages Options Flag Default Description --- --- --- --api off Start the REST API server -p , --port 8080 Port for the API server -r , --runner runner.yml Path to the runner configuration file --stdin off Rea","default_branch":null,"files":null,"tree":[],"storefront":"/r/clicksiem","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/clicksiem/clickdetect/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}