How To Use The Elastic Stack as a SIEM - John Hubbard

แชร์
ฝัง
  • เผยแพร่เมื่อ 14 ต.ค. 2024

ความคิดเห็น • 21

  • @Nurof3n_
    @Nurof3n_ 5 หลายเดือนก่อน +1

    I learned so many things from this and not just about the elastic stack

  • @MisterOA
    @MisterOA 3 ปีที่แล้ว +7

    This is definitely one of the best resources on the internet on the subject. Thank you for sharing John.

  • @shameersirajuddin1490
    @shameersirajuddin1490 ปีที่แล้ว

    Masterful way of introducing a complex topic and diving deep and still keep it interesting, relevant & comprehensive. I wish more creators share your clarity

  • @EasyMac308
    @EasyMac308 5 ปีที่แล้ว +5

    This should definitely have more views. I found it via John Hagen's SOF-ELK SANS webcast. Thanks!

  • @fernandoalencar3767
    @fernandoalencar3767 2 ปีที่แล้ว +1

    Amazing content!
    Still a lot applies until today!
    Thanks John!

  • @Z0nd4
    @Z0nd4 5 ปีที่แล้ว +2

    Great video! Please do more videos of ELK SIEM

  • @vuhaiang2852
    @vuhaiang2852 2 ปีที่แล้ว

    Excellent content, brilliant work you 've done there. Thank you so much for making this video. Feel lucky to find your channel

  • @ravis3754
    @ravis3754 2 ปีที่แล้ว

    Thank you Jon for this awesome content put together.

  • @GMDGeek
    @GMDGeek 5 ปีที่แล้ว +1

    Going to give this a watch tonight - curious to see if you discuss limitations or infrastructure to run it large scale.

  • @dbencomo
    @dbencomo 5 ปีที่แล้ว

    Very interesting talk, a complement for SEC555, thanks you John.

  • @mauriziodalre7360
    @mauriziodalre7360 4 ปีที่แล้ว +1

    Very interesting, but one of the main features of a SIEM is correlation: how to implement simple/complex correlation rules in ELK?

  • @ashutosh567
    @ashutosh567 5 ปีที่แล้ว

    great learning material! May be some example of logstash conf file with firewall configuration would be useful!

  • @ivan_torres
    @ivan_torres 3 ปีที่แล้ว

    Thank you so much for this video, I really appreciate your knowledge and efforts!!!

  • @twistable_deer
    @twistable_deer 5 ปีที่แล้ว

    Very good video. Thank you!

  • @RichardBejtlich
    @RichardBejtlich 5 ปีที่แล้ว +1

    Very helpful, thank you John.

  • @VIPMakhana
    @VIPMakhana ปีที่แล้ว

  • @kepenge
    @kepenge 3 ปีที่แล้ว

    Is there any recommendations for distributed architecture hardware requirements?

  • @Schlumpfpirat
    @Schlumpfpirat 5 ปีที่แล้ว

    Hey, something that was unclear - why do you send the data to LogStash with FileBeat, as it only seems to be able to create one fixed Index, while your Kibana source showed a more granular, date-increasing FileBeat Index, indicating that you sent the data directly to Elasticsearch. If you could elaborate on that, that'd be cool.
    Also I'm not quite sure I got the hang of what the benefit of using LogStash vs Elasticsearch as a collector is; I get that you can somehow "enrich" data, which sounds good, but is actually unclear to how it fares in a production scenario.

  • @dbencomo
    @dbencomo 5 ปีที่แล้ว

    Jonh, are slides available somewhere?

  • @khaledshokry9223
    @khaledshokry9223 5 ปีที่แล้ว

    Thank you!!

  • @rockade2408
    @rockade2408 4 ปีที่แล้ว

    Your explanation of Schema is completely WRONG.