Security analytics for Laravel — security event logging, anomaly detection, threat intelligence, SIEM export (Splunk, Datadog, Elasticsearch, syslog), incident response, alerting, and dashboards.
artisanpack-ui/security-analytics is a Laravel package for security analytics for laravel — security event logging, anomaly detection, threat intelligence, siem export (splunk, datadog, elasticsearch, syslog), incident response, alerting, and dashboards..
It currently has 0 GitHub stars and 237 downloads on Packagist (latest version 1.1.0).
Install it with composer require artisanpack-ui/security-analytics.
Discover more Laravel packages by artisanpack-ui
or browse all Laravel packages to compare alternatives.
Last updated
Security analytics for Laravel: structured security event logging, pluggable anomaly detection, threat intelligence aggregation, SIEM export (Datadog / Elasticsearch / Splunk / Syslog / Webhook), playbook-driven incident response automation, multi-channel alerting, reports, and a Livewire dashboard.
This package is part of the ArtisanPack UI Security 2.0 split — the analytics, monitoring, and incident-response features previously bundled inside artisanpack-ui/security (1.x) live here in 2.0+.
SecurityEventLogger plus a LogAuthenticationEvents listener that captures Laravel auth events automatically into a structured security_events table.BruteForce, CredentialStuffing, GeoVelocity, PrivilegeEscalation, AccessPattern, Behavioral, Statistical, RuleBased) orchestrated by AnomalyDetectionService with per-user baselines via BaselineManager.AbuseIPDB, GoogleSafeBrowsing, IpQualityScore, VirusTotal, CustomFeed) aggregated by ThreatIntelligenceService.Datadog, Elasticsearch, Splunk, Syslog, Webhook) backed by SiemExportService.IncidentResponder and driven by ResponsePlaybook definitions.Database, Email, OpsGenie, PagerDuty, Slack, Sms, Teams, Webhook) routed via AlertManager with AlertRule definitions and AlertHistory audit.ExecutiveSummary, Incident, Compliance, Threat, Trend, UserActivity) generated on-demand or on a schedule via ScheduledReport.SecurityDashboardController (10 JSON endpoints) plus 4 Livewire components (SecurityDashboard, SecurityEventList, SecurityStats, SuspiciousActivityList) with shipped Blade views.SecurityEventOccurred, AnomalyDetected, SuspiciousActivityDetected — subscribe to integrate with downstream systems.SecurityAnalytics Facade + security_analytics() helper.The package registers three AI-assisted surfaces via artisanpack-ui/ai when installed. Each is a plain Livewire component wired to an agent that extends ArtisanPackUI\Ai\Agents\ArtisanPackAgent, so it inherits the shared feature toggle, credential resolver, cache pipeline, and usage tracking.
| Feature key | Agent | Livewire component | Default model | Purpose |
|---|---|---|---|---|
| security.threat_triage | ThreatTriageAgent | ThreatTriagePanel | claude-sonnet-4-6 | Plain-language severity and recommended actions for a single SecurityEvent. |
| security.anomaly_summary | AnomalySummaryAgent | AnomalySummaryPanel | claude-haiku-4-5-20251001 | Periodic digest of unusual events over a configurable window (default 24h). |
| security.incident_response | IncidentResponseAgent | IncidentResponsePanel | claude-opus-4-7 | Suggested next steps for an open SecurityIncident. Advisory only — never triggers actions. |
Features are discovered automatically from the service provider's aiFeatures() method by the artisanpack-ui/ai boot pass — no manual registration required. Each feature is togglable at runtime via the shared feature registry, and each Livewire panel renders a disabled state when the feature is off or when credentials cannot be resolved (no LLM calls happen in either case).
Render a panel inline anywhere you have an event or incident:
{{-- On the security-event detail surface --}}
<livewire:security-analytics.threat-triage-panel :event-id="$event->id" />
{{-- Somewhere on the dashboard --}}
<livewire:security-analytics.anomaly-summary-panel />
{{-- On the incident detail surface --}}
<livewire:security-analytics.incident-response-panel :incident-id="$incident->id" />
The three agents are also invocable directly from PHP:
use ArtisanPackUI\SecurityAnalytics\AI\Agents\ThreatTriageAgent;
$triage = ThreatTriageAgent::for( $securityEvent )->run();
// [ 'severity' => 'high', 'summary' => '…', 'recommended_actions' => [ … ], 'related_events' => [ … ] ]
Override the shipped Blade views by shadowing them under resources/views/vendor/security-analytics/livewire/{threat-triage-panel,anomaly-summary-panel,incident-response-panel}.blade.php.
composer require artisanpack-ui/security-analytics
php artisan migrate
(Optional) Publish the config:
php artisan vendor:publish --tag=security-analytics-config
Log a security event:
use ArtisanPackUI\SecurityAnalytics\Facades\SecurityAnalytics;
security_analytics()->logger()->log(
type: 'authentication',
name: 'login.failed',
severity: 'warning',
context: ['username' => $request->input('email')],
);
Or react to the auth events Laravel fires:
// The package's LogAuthenticationEvents listener wires this up automatically.
// To opt out, set config('artisanpack.security-analytics.auto_log_auth_events') to false.
Mount the dashboard:
// The dashboard routes auto-register under the configured prefix (default: /security).
// Visit /security/dashboard to see the Livewire UI.
The dashboard views ship as plain HTML + Tailwind by design — the package does not depend on artisanpack-ui/livewire-ui-components. To customize them, shadow the package views by placing your own files at resources/views/vendor/security-analytics/livewire/*.blade.php — Laravel resolves overrides before package defaults.
artisanpack-ui/ai ^1.0.0-alpha.1 — foundation for the three AI features (see AI features)livewire/livewire ^3.6 or ^4.0 (only required for the dashboard UI + AI panels; the rest of the package works without Livewire)| Package | Scope |
|---|---|
| artisanpack-ui/security-full | Meta-package — pulls in the full security suite (all six packages below) in a single require |
| artisanpack-ui/security | Core: input sanitization, escaping, CSP, security headers |
| artisanpack-ui/security-auth | 2FA, password complexity, account lockout, sessions |
| artisanpack-ui/security-advanced-auth | WebAuthn, SSO, social login |
| artisanpack-ui/rbac | Roles, permissions, Gate integration |
| artisanpack-ui/secure-uploads | File validation, malware scanning, signed-URL serving |
| artisanpack-ui/compliance | GDPR / CCPA / LGPD compliance tools |
MIT — see LICENSE.
Please read the contributing guidelines before opening an issue or PR.