Collector Service - zakharb/labshock GitHub Wiki
Labshock includes Collector Service The Collector Service in Labshock is responsible for gathering logs, events, and network traffic from different OT components, including PLCs, SCADA systems, IDS, and other services. It plays a critical role in feeding data to OT SIEM for monitoring, analysis, and threat detection.
Collector Service Features:
- Log Aggregation – Collects logs from SCADA, PLCs, IDS, and other Labshock services
- Forwarding to SIEM – Sends collected data to OT SIEM or external logging platforms
Labshock includes Tidal Collector for efficient OT data collection and forwarding.
Features:
- Collect logs and metrics from OT devices
- Normalize and forward data to SIEM
- Filter and enrich data before forwarding
- Lightweight and efficient
- Web based: simple & easy
Use Cases:
- Centralize OT data collection for analysis
- Enhance SIEM visibility with OT-specific logs
- Normalize diverse log formats
- Reduce noise with smart filtering
- open web interface http://localhost:2443/
- go to Messages tab
- you can filter and search data

- go to Sources tab
- you can see full list of sources
