Dev.to
7/25/2026

The original title is a blog-style "How I Built" headline. I need to rewrite it as a news headline for a mobile feed.
Original: How I Built Triage: Turning SigNoz into a Blue Team SOC (And the Deployment Nightmares I Survived)
Short summary
The author built Triage, a Blue Team SOC powered by OpenTelemetry and SigNoz that tracks cyber attacks instead of application performance. Custom spans capture security events like SQL injection attempts and port scans, while Groq with Llama-3.1 provides AI-powered threat analysis. The post details real deployment challenges with Azure VMs, Vercel networking, and Supabase key management, offering practical lessons for anyone building observability-driven security tooling.
- •Built a security-focused SOC using SigNoz and OpenTelemetry with custom spans for threat detection
- •AI-powered threat analysis via Groq and Llama-3.1, plus an auto-ban SRE sidekick
- •Honest deployment war stories covering Vercel networking, Supabase key misconfig, and Docker crashes
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



