Module 17: SIEM Part One: Intro to ELK
Log Management Introduction
SIEM Concepts


Elastic Stack (ELK)


ELK Integrations with OSQuery


agent
directory
filename
agent
address
name
pid
port
agent
local_address
local_port
name
pid
remote_address
port
ELK Security
Rules and Alerts




Timelines and Cases



@timestamp
message
event.category
event.action
host.name
source.ip
destination.ip
user.name




Last updated