How To Setup ELK | Elastic Agents & Sysmon for Cybersecurity

แชร์
ฝัง
  • เผยแพร่เมื่อ 21 ธ.ค. 2024

ความคิดเห็น •

  • @medericburlet6097
    @medericburlet6097 ปีที่แล้ว +46

    I deployed and installed ELK for my company recently! Would love to see more content on log monitoring and detection!

    • @dilpreetkohli6630
      @dilpreetkohli6630 ปีที่แล้ว +1

      hey, do you have more resources for the same? I wanna learn this before I land for my job

  • @natestoutrt
    @natestoutrt ปีที่แล้ว +10

    This is exactly what I'm doing next week after classes end. Thanks!

  • @woaq4486
    @woaq4486 3 หลายเดือนก่อน +1

    Following this guide to install as well as others for config and detection development helped me land a job as a detections engineer. Great content as always!

  • @berkderooij2046
    @berkderooij2046 ปีที่แล้ว +7

    5:11 Bless you!

  • @jjann54321
    @jjann54321 ปีที่แล้ว +23

    Thanks John, great content as always! Maybe doing a demo on spinning up a SecurityOnion VM would be helpful for many of your "Blue Team" viewers.

    • @edwardlenovo3240
      @edwardlenovo3240 ปีที่แล้ว +2

      was going to say...Security Onion, preconfigured ELK SIEM, makes life way easier.

    • @zytoe3910
      @zytoe3910 11 หลายเดือนก่อน

      Yes please do this

  • @javirebeld
    @javirebeld ปีที่แล้ว +5

    You have been dropping so much content recently, thanks man 🔥🔥

  • @AndreaKim312
    @AndreaKim312 ปีที่แล้ว +1

    BHIS/Antisyphon/WWHF are AWESOME!!!
    I'M A HUGE FAN.

  • @Diamond_Chocobo
    @Diamond_Chocobo 6 หลายเดือนก่อน

    i finished the Lab!! Thanks Super fun!
    in the discover section of Kabana,... thank you for showing us that filter section,... it reminds me of the filter section in Wireshark in order to reduce the number of network packets in the PCAP file,... in this case your using a filter to reduce the number of documents in order to make it easier to scan for what your looking for.
    i learned many things so far!
    like you cant add policies to an agent,... but you can add agents to a policy!
    GOOD STUFF!!

  • @Zevilon05
    @Zevilon05 5 หลายเดือนก่อน +1

    Since some of this relates, I would love to see you do a full video on Security Onion. It there isn’t much coverage on it.

  • @bangbinbash
    @bangbinbash ปีที่แล้ว

    Aahh! Was literally just doing this on my own a week ago, perfect timing!

  • @onemoreguyonline7878
    @onemoreguyonline7878 ปีที่แล้ว

    It's fun to see the setup of a platform that I've used before.

  • @Raima888s
    @Raima888s ปีที่แล้ว

    Thanks for the video. Helping our Siem group understand these tools in security onion.

  • @FaLkraydz
    @FaLkraydz 2 หลายเดือนก่อน

    Is it realistic to start a business with the ELK Stack? Maybe use snort as well? Use 100% open source solution at least for the first couple years and then cut over?

  • @jjones503
    @jjones503 11 หลายเดือนก่อน

    Is there a way to self host elastic or something similar, $95 a month is a bit steep.

  • @darkfro08
    @darkfro08 ปีที่แล้ว

    Love the shirt. I rock the same one at the office.

  • @cybr774
    @cybr774 ปีที่แล้ว

    Wazuh is almost the same right? I heard that it uses the ELK stack

  • @tametov
    @tametov ปีที่แล้ว

    This content is brilliant.

  • @ReligionAndMaterialismDebunked
    @ReligionAndMaterialismDebunked ปีที่แล้ว +1

    That sneeze zoom. Hahahaha. Creative! :3 🎉😂💀😅🔥🤡🤝😁🔥🔥😎

  • @Zelazella1
    @Zelazella1 4 หลายเดือนก่อน +1

    more content on log monitoring and detection plz

  • @muhamadfachri6122
    @muhamadfachri6122 ปีที่แล้ว

    How can John get the 150 day trial?

  • @djones0105
    @djones0105 ปีที่แล้ว

    Thank you, John! Very informative.

  • @RoughGanome
    @RoughGanome ปีที่แล้ว +2

    The ELK stack is awesome. But Splunk is king 👑. Great content! Keep up the great work.

  • @BabyPowder013
    @BabyPowder013 11 วันที่ผ่านมา

    You are awesome!

  • @bradfoster4198
    @bradfoster4198 ปีที่แล้ว

    Thanks John! Question : this seems to all hinge upon sysmon which is not installed by default in Windows. Is the idea here than an org would rollout sysmon widespread as a logging agent for company workstations?

  • @rishabhshrivastava1870
    @rishabhshrivastava1870 ปีที่แล้ว

    I have deployed a website using devsecops methodology, I want to use elk for the last stage i.e monitoring. What are the steps to integrate?

  • @bhaveshkathore3746
    @bhaveshkathore3746 3 หลายเดือนก่อน

    How can I get syslog ?? Please comments

  • @rahulramteke3338
    @rahulramteke3338 ปีที่แล้ว

    Can you do a full course here on YT on Kali Purple?

  • @bluesquare23
    @bluesquare23 ปีที่แล้ว +1

    I use kibana at work. It's okay. I kinda like just raw log reading better. But the elk stack has its place.

  • @toptechtowing6340
    @toptechtowing6340 ปีที่แล้ว

    Omgggg I want that shirt !!!

  • @freem4nn129
    @freem4nn129 ปีที่แล้ว

    Love the shirt John :D

  • @rodetzky9833
    @rodetzky9833 ปีที่แล้ว

    Love your videos!!!

  • @Lampe2020
    @Lampe2020 ปีที่แล้ว +2

    5:10 That wasn't worth the warning. I thought a loud beep would happen but that sneeze was not loud at all. I sneeze much louder, kinda like my stepgrandfather did.

  • @JoshuaDiamente
    @JoshuaDiamente ปีที่แล้ว +1

    Hi John, thanks for your videos. Quick question: In terms of security and spying, is it better to dual boot a Kali distro or run it in a VM? I'm almost certain windows can spy on the VM through virtual box software but I'm wondering if a dual boot would be any more secure considering I'm running an AMD system and realistically there would be a backdoor some where.
    Would love to hear your thoughts. Thanks in advance!

  • @elisehackmann-tf6xg
    @elisehackmann-tf6xg ปีที่แล้ว

    Please make more videos about Elastic! like setting rules for alerts or how to integrate with EDR, IPS or Firewall or Antivirus. Would really be nice

    • @bluxombie
      @bluxombie ปีที่แล้ว

      That would be nice. Rules and alerts are pretty simple. Hopefully he will do something like that for you all.
      If you're looking at pulling firewall etc. I recommend looking at using filebeat or set up agent and deploy that on your host. That'll give you out of the box parsing and kibana dashboards from the get go for that or syslog, or f5, or whatever module you enable.
      There's pros and cons to both, and while I prefer to use beats for certain reasons, agent can be great. Especially when you have a lot of hosts and want to use fleet to manage everything. While beats are more flexible to the user, fleet agent makes more sense in large environments.
      We can use integrations of the left menu as well, add and manage right there in kibana if you don't like going in the terminal.
      Pretty much exactly how he added is how you add any integration. Some of course require certain information such as the the email integration.
      Are there any areas that are of particular problems you need help with?

  • @sifedinebibi4467
    @sifedinebibi4467 ปีที่แล้ว

    Could you kindly provide us with a video for SIEM Splunk Enterprise? We appreciate all the efforts you have made thus far. Thank you.

  • @MurtazaSalman-v2k
    @MurtazaSalman-v2k 4 หลายเดือนก่อน

    Do a video on Security Onion

  • @AlfredNobel-u1u
    @AlfredNobel-u1u 2 หลายเดือนก่อน

    [Y/n] already means yes by default!

  • @guitargrin
    @guitargrin ปีที่แล้ว

    I too like typing CD over and over😂

  • @dtitan1993
    @dtitan1993 ปีที่แล้ว

    -n is for network

  • @maximilian5859
    @maximilian5859 ปีที่แล้ว

    Honestly I don’t know why Logstash is still a thing. Even elastic pushes the Agent so much and with all the integrations it is possible to send most of the logs directly without Logstash. It could be useful when a lot of data needs to be parsed and you won’t pay the CPU usage in the cloud

  • @Stopinvadingmyhardware
    @Stopinvadingmyhardware ปีที่แล้ว +1

    Seeing Bash commands on Windows still bothers me

  • @codingdude8782
    @codingdude8782 5 หลายเดือนก่อน

    bless you

  • @garbagetrash2938
    @garbagetrash2938 ปีที่แล้ว

    I could’ve used this a month ago 😭😭😭😭 I just set my home instance up.

  • @wintermute111
    @wintermute111 ปีที่แล้ว

    You know that [Y/n] Yes is default option and hitting enter will assume Y? (it's quite common in Linux)

  • @DeadlyDragon_
    @DeadlyDragon_ ปีที่แล้ว +2

    John I wish to introduce you to Wazuh, which is backed by opensearch and kibana and has an agent that runs on each host. Saves you from having to do this all yourself!

  • @WaseemLaghari
    @WaseemLaghari ปีที่แล้ว

    5:11 say Alhamdulillah

  • @charlescabage730
    @charlescabage730 ปีที่แล้ว

    Video spree

  • @bluesquare23
    @bluesquare23 ปีที่แล้ว

    Takes John Hammond 14 minutes to do this. Took me many hours :(

  • @tyrojames9937
    @tyrojames9937 ปีที่แล้ว

    👍🏾

  • @Pik92
    @Pik92 ปีที่แล้ว

    why is your windows user called adhd ...

  • @ReligionAndMaterialismDebunked
    @ReligionAndMaterialismDebunked ปีที่แล้ว

    Early :3

  • @JHORAMCANOYNARSICO
    @JHORAMCANOYNARSICO 2 หลายเดือนก่อน

    way pulos

  • @isaaclakra382
    @isaaclakra382 ปีที่แล้ว

    elastic cloud after 14 days trial ......WE have to DELETE this lab after 14 days...

    • @JosueHernandez-nj9bc
      @JosueHernandez-nj9bc 2 หลายเดือนก่อน

      Cloud is never free host it locally or use linode for the cheap

  • @malachie4tabernacle523
    @malachie4tabernacle523 2 หลายเดือนก่อน

    you talk too fast. can you slow down for us to follow you