Baruch is the central SIEM and flow engine for SoftSol's out-of-band SOC — ingesting NetFlow, syslog, and Wazuh agent telemetry from certified SoftSol MikroTik routers in the field. Cloud Core and other higher-end RouterOS platforms are supported.
Named for the scribe who recorded the deeds of kings — Baruch is the notary layer of The Witnesses architecture. Every flow record, firewall event, and agent alert is indexed for search, correlation, and long-horizon retention.
Single-node Wazuh stack with OpenSearch indexer tuned for 32 GB RAM — manager, indexer, and dashboard orchestrated via Docker.
Collects NetFlow v9 and IPFIX from client routers, normalises records, and writes directly into the archive indexer.
Elisha and future edge witnesses register here on port 1515 and stream alerts on 1514/tcp.
Configure certified SoftSol MikroTik routers and agents to target these addresses over the WireGuard VPN.
NetFlow / IPFIX → ElastiFlow collector
Wazuh agent event stream
Remote syslog (firewall, system)