2013-09-04 07:49 PM
I recently purchased a starter kit of the Philips Hue lighting system. http://www.meethue.com Why? They are wifi enabled multi-coloured light bulbs that can be programmed using a REST API. In my endless search to justify the $249 price of three light bulbs I came up with a crazy idea. What if I integrated the Hue lights into my SA 10.x deployment. About 15 minutes later I had invented the first (to my knowledge) SA lighting effects and alerting solution.
The Hue bulbs work with a smart phone app or anything that can talk to the REST API of the base station. This base station can turn on and off the lights or change the "hue" of each globe to reproduce any colour. You can program the controller directly using REST calls (e.g. http://ip.addr/lights/on) or make use of any number of third party email-to-hue solutions. I am using one of these third-party systems from IFTTT. Just sign up for an account under an email address that your SA RE box can use and configure your Hue controller to talk via the web site.
The first step is to define some if-then-that rules. I've created some basic ones that will trigger on tags, such as #SSL here. An email sent from the SARE alert to trigger@ifttt.com with the subject #SSL with trigger an action. In this case, it will turn on all my Hue lights red. Other actions include blinking lights, cycling colours, turning off and on lights etc. You could define different colours for different alerts... let your inner child go wild.
Back in SA you will need to create some SMTP alerts that mirror the ifttt.com rules. Here is a simple rule that will trigger the #SSL rule and turn the lights red.
http://developers.meethue.com/coreconcepts.html The Philips Hue system has a full REST API so if anyone is keen to build a direct SA REST to Hue REST solution go nuts but please share.
Justification for $69 light globes is hard but the coolness factor of being alerted to outbound covert channels when your entire office lights up in red is priceless.
2013-09-05 10:29 AM
Was this a paid promo? Not sure if trolling....
2013-09-05 10:35 AM
It must be pretty elaborate trolling if that was the intent... built a SA server just to sell light bulbs.
Gees you security people are so paranoid. 😉
2013-09-05 04:05 PM
Love it. Alert type mood lighting...Red flashing light means this....blue means that....brings a little fun to the detection and investigative process!
2013-09-16 11:01 AM
pretty cool. I want a literal Red Alert in our CIRC now.
2013-09-17 08:16 AM
Seth I can't find the "Dislike" link for your post
2013-09-17 08:28 AM
I've set up my SA "mood lighting" to change colour based on the Country of origin of the alert. i.e. Red = China, Green = Brazil, Blue = US etc.
Strangely, my office is now permanently coloured red.