CNSL
Correlated Network Security Layer
A self-hosted SIEM for Linux.
Detects attacks that span SSH, web, database, and cloud logs simultaneously -- then blocks them automatically.
What it does
Most tools watch one log and count failures. CNSL watches everything at once.
When an attacker scans your web server, probes your database, then tries SSH with stolen credentials -- CNSL sees all three as one coordinated attack and responds before the breach completes.
Web scan from 45.33.32.1 --+
SSH brute from 45.33.32.1 --+---> HIGH alert + auto-block
DB auth fail from 45.33.32.1 --+
It also tracks how far each attacker has progressed through the kill chain, learns new attack patterns automatically, and shares threat intelligence across multiple servers in real time.
Beyond core detection: multi-node federation with a unified hub view, STIX 2.1 export and a built-in TAXII 2.1 server for sharing IOCs, Wazuh/OSSEC integration, PostgreSQL support with a migration tool, a Kubernetes Helm chart, attacker fingerprinting (spots the same actor rotating IPs), graph-based campaign correlation, and opt-in predictive blocking that reacts to an attack's trajectory before any single rule's threshold fires.
Quick start
pip install cnsl[full]
sudo python -m cnsl --dashboard --no-tcpdump
# Open http://127.0.0.1:8765
# Default login: admin / cnsl-change-me
Or from source:
git clone https://github.com/rahadbhuiya/cnsl.git
cd cnsl
python3 -m venv venv && source venv/bin/activate
pip install -e ".[full]"
sudo venv/bin/python -m cnsl --dashboard --no-tcpdump
Start in dry-run mode (default) -- no real blocks until you add
--execute.
Or on Kubernetes (one DaemonSet pod per node, protecting every node in the cluster):
helm install cnsl ./helm/cnsl --namespace cnsl --create-namespace
See docs/kubernetes.md and helm/cnsl/README.md for the full walkthrough (federation, the multi-node hub view, enabling real blocking).
Dashboard
Enable with --dashboard. Runs at http://127.0.0.1:8765.
Tabs: Overview, Incidents, Blocks, Live Feed, Kill Chain, Graph, Correlation, Hub, Campaigns, Cases, UEBA, ML, Honeypot, FIM, Rules, Rate Limit, Settings.
For remote access use an SSH tunnel:
ssh -L 8765:127.0.0.1:8765 user@yourserver
Configuration
Copy and edit the example config:
cp config/config.example.json /etc/cnsl/config.json
All options are documented in docs/configuration.md.
Key sections: thresholds, actions, dashboard, notifications, redis, cloud_identity, zero_trust, siem, federation.
Documentation
| Document | What it covers |
|---|---|
docs/installation.md |
Full install, systemd, Docker |
docs/configuration.md |
Every config option explained |
docs/features.md |
Complete feature list |
docs/architecture.md |
Module structure and design |
docs/api.md |
Full REST API reference |
docs/kubernetes.md |
Helm chart deployment (DaemonSet, hub view, federation) |
docs/kill-chain.md |
Kill chain tracker (predictive blocking: see docs/api.md) |
docs/federation.md |
Multi-node setup and the hub view |
docs/cloud-identity.md |
AWS + Azure AD + GCP integration |
docs/sigma-rules.md |
Sigma detection rule import |
docs/attack-mapping.md |
MITRE ATT&CK technique tagging and coverage |
docs/oidc-sso.md |
OIDC single sign-on setup |
docs/source-health.md |
Log source silence detection |
docs/retention.md |
Data retention and archival |
docs/zero-trust.md |
Trust score engine |
docs/siem-connectors.md |
Splunk, Sentinel, Webhook push |
docs/pattern-learning.md |
Automated rule discovery |
docs/rules.md |
Detection rule tuning (correlation-rule tuning: see docs/api.md) |
docs/ueba.md |
User/entity behavior analytics |
docs/cases.md |
Case management |
docs/threat-feed.md |
External threat feed ingestion |
docs/2fa.md |
Two-factor auth for the dashboard |
docs/agent.md |
Remote log-shipping agent |
docs/kafka.md |
Kafka log ingestion |
docs/zeek.md |
Zeek log integration |
docs/ot-iot.md |
OT/ICS protocol support (Modbus, DNP3, SCADA) |
docs/country-blocking.md |
Geo-based blocking |
docs/rate-limiting.md |
API rate limiting |
docs/tenants.md |
Multi-tenant setup |
docs/huddle.md |
Incident huddle/collaboration |
docs/notifications.md |
Email/Slack/Telegram alerts |
docs/changelog.md |
Version history |
docs/ |
Browse all 32 guides |
Requirements
- Linux (Ubuntu 20.04+ / Debian 11+ / RHEL 8+)
- Python 3.10+
- Root or
CAP_NET_ADMINfor iptables blocking
Optional: Redis (distributed blocklist + federation), MaxMind GeoIP database.
License
MIT. See LICENSE.
Release files for cnsl 3.4.25
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| cnsl-3.4.25.tar.gz | 375.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| cnsl-3.4.25-py3-none-any.whl | Python 3 | none | any | Details |
Total release size:691.1 kB
Release files / cnsl-3.4.25.tar.gz
| Download URL | cnsl-3.4.25.tar.gz |
|---|---|
| Size | 375.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
3d588e89bfecebe49345b4f539fd61b38e805a43e46b54351e4b568607074576
|
|
BLAKE2b-256 checksum How to use checksums |
9cf6cad06902727e8d5b9e09d05d0b4a06b07b5ccd4803b742e0fcc774f1541a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 19, 2026.
Transparency logRelease files / cnsl-3.4.25-py3-none-any.whl
| Download URL | cnsl-3.4.25-py3-none-any.whl |
|---|---|
| Size | 315.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
223343f9b2254ab6928c939186855ad4b7828636163ee4a090803217abd612bd
|
|
BLAKE2b-256 checksum How to use checksums |
59747f6559c94ac022d85867952606bd707ec5698451f4b3054850defd41bd34
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 19, 2026.
Transparency log