Skip to content

About

Export NetBird audit events to Loki, Wazuh, HTTP, and syslog sinks.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

6 stars

Watchers

0 watching

Forks

Repository files navigation

AuditBridge

AuditBridge reads NetBird audit events and delivers them independently to Grafana Loki, Wazuh, and generic HTTP or syslog destinations. It is a small Rust service for security monitoring, compliance evidence, and incident response.

flowchart LR
  NetBird[NetBird audit API] --> AuditBridge[AuditBridge]
  AuditBridge --> Loki[Grafana Loki]
  AuditBridge --> Wazuh[Wazuh syslog]
  AuditBridge --> HTTP[HTTP or syslog sink]
Loading

Quick start

Get a NetBird access token (Team > create a Service User > create an access token, see Installation for exact steps), store it in a file, then run a released immutable image:

echo "nbp_your_token_here" > netbird-token
chmod 600 netbird-token

docker run -d --rm --name auditbridge \
  -v "$PWD/netbird-token:/run/secrets/netbird-token:ro" \
  -e NETBIRD_API_TOKEN_FILE=/run/secrets/netbird-token \
  -e LOKI_URL=https://loki.example.com \
  -p 9090:9090 \
  ghcr.io/onelrian/auditbridge:<immutable-tag>

Warning

Replace <immutable-tag> with a released application version. Do not use latest in a production deployment, it moves whenever a new release ships.

Confirm it's running: docker logs auditbridge and curl http://localhost:9090/healthz.

Documentation

Need Guide
Deploy with Docker, Compose, Kubernetes, or Helm Installation
Configure secrets, retries, cursors, and metrics Configuration
Deliver to Loki, Wazuh, HTTP, or syslog Sinks
Monitor and troubleshoot the service Operations
Develop and submit changes Contributing
Report vulnerabilities Security
Get help or report a defect Support

Health and metrics

AuditBridge serves /healthz, /readyz, and /metrics on METRICS_PORT (default 9090). Readiness requires a successful NetBird fetch and delivery to at least one configured sink. See Operations for metric names and troubleshooting.

Verified

Every sink type is verified end to end in examples/local-demo: real Loki, real TCP and UDP syslog receivers, a real HTTP webhook receiver, and AuditBridge's actual binary — only the NetBird API is stubbed to fixed sample data, no live account involved. The evidence below is real output captured from that compose stack, reproduced with one docker compose up -d --build.

Sink Delivery Captured evidence
Grafana Loki SINKS=loki Loki query response, one stream per activity, nanosecond timestamps
Wazuh SINKS=wazuh, SINK_WAZUH_ADDR RFC 3164 frames received over TCP
Generic HTTP SINK_<NAME>_TRANSPORT=http application/x-ndjson POST /ingest received at the webhook
Generic syslog SINK_<NAME>_TRANSPORT=syslog RFC 5424 frames received over UDP

Each section in Sinks pairs the complete configuration with its verification commands and the captured output, including readyz/metrics showing per-sink delivered totals.

Tip

Don't take this page's word for it: examples/local-demo/ reproduces the exact setup with one command, and every block above is re-capturable from its logs and endpoints. See examples/local-demo/README.md.

License

Distributed under the MIT License. See LICENSE.

About

Export NetBird audit events to Loki, Wazuh, HTTP, and syslog sinks.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

6 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages