In the realm of security, open source has a much smaller footprint than in other IT ecosystems. At Booking.com, we found ourselves swimming deep in a multitude of black box solutions, duplicated workflows, overlapping and incompatible schemas, multiple data lakes on different stacks, and more. This is on top of the challenge of a very heterogeneous set of stakeholders, ranging from Cyber Security Analysts, to Developers and Machine Learning scientists. Apache Flink was chosen as the engine for providing all security data processing, with an overlying application framework meant to abstract complexity from building data processing pipelines, into a single unified extensible schema.
by
David Ponessa & Pedro Ceriotti
Booking.com