How To Use The Elastic Stack as a SIEM - John Hubbard

  Рет қаралды 56,758

John Hubbard

John Hubbard

Күн бұрын

Пікірлер: 21
@MisterOA
@MisterOA 4 жыл бұрын
This is definitely one of the best resources on the internet on the subject. Thank you for sharing John.
@shameersirajuddin1490
@shameersirajuddin1490 Жыл бұрын
Masterful way of introducing a complex topic and diving deep and still keep it interesting, relevant & comprehensive. I wish more creators share your clarity
@Nurof3n_
@Nurof3n_ 9 ай бұрын
I learned so many things from this and not just about the elastic stack
@EasyMac308
@EasyMac308 5 жыл бұрын
This should definitely have more views. I found it via John Hagen's SOF-ELK SANS webcast. Thanks!
@fernandoalencar3767
@fernandoalencar3767 2 жыл бұрын
Amazing content! Still a lot applies until today! Thanks John!
@vuhaiang2852
@vuhaiang2852 2 жыл бұрын
Excellent content, brilliant work you 've done there. Thank you so much for making this video. Feel lucky to find your channel
@ravis3754
@ravis3754 2 жыл бұрын
Thank you Jon for this awesome content put together.
@Z0nd4
@Z0nd4 5 жыл бұрын
Great video! Please do more videos of ELK SIEM
@GMDGeek
@GMDGeek 6 жыл бұрын
Going to give this a watch tonight - curious to see if you discuss limitations or infrastructure to run it large scale.
@dbencomo
@dbencomo 5 жыл бұрын
Very interesting talk, a complement for SEC555, thanks you John.
@kepenge
@kepenge 3 жыл бұрын
Is there any recommendations for distributed architecture hardware requirements?
@ashutosh567
@ashutosh567 5 жыл бұрын
great learning material! May be some example of logstash conf file with firewall configuration would be useful!
@twistable_deer
@twistable_deer 5 жыл бұрын
Very good video. Thank you!
@mauriziodalre7360
@mauriziodalre7360 5 жыл бұрын
Very interesting, but one of the main features of a SIEM is correlation: how to implement simple/complex correlation rules in ELK?
@ivan_torres
@ivan_torres 3 жыл бұрын
Thank you so much for this video, I really appreciate your knowledge and efforts!!!
@RichardBejtlich
@RichardBejtlich 5 жыл бұрын
Very helpful, thank you John.
@dbencomo
@dbencomo 5 жыл бұрын
Jonh, are slides available somewhere?
@khaledshokry9223
@khaledshokry9223 5 жыл бұрын
Thank you!!
@Schlumpfpirat
@Schlumpfpirat 5 жыл бұрын
Hey, something that was unclear - why do you send the data to LogStash with FileBeat, as it only seems to be able to create one fixed Index, while your Kibana source showed a more granular, date-increasing FileBeat Index, indicating that you sent the data directly to Elasticsearch. If you could elaborate on that, that'd be cool. Also I'm not quite sure I got the hang of what the benefit of using LogStash vs Elasticsearch as a collector is; I get that you can somehow "enrich" data, which sounds good, but is actually unclear to how it fares in a production scenario.
@Annraj_Foods
@Annraj_Foods Жыл бұрын
@rockade2408
@rockade2408 4 жыл бұрын
Your explanation of Schema is completely WRONG.
Beginner's Crash Course to Elastic Stack -  Part 1: Intro to Elasticsearch and Kibana
56:42
Beat Ronaldo, Win $1,000,000
22:45
MrBeast
Рет қаралды 158 МЛН
SOF ELK®  A Free, Scalable Analysis Platform for Forensic, Incident Response, and Security Operation
1:02:37
SANS Digital Forensics and Incident Response
Рет қаралды 34 М.
How To Setup ELK | Elastic Agents & Sysmon for Cybersecurity
14:35
John Hammond
Рет қаралды 88 М.
Elasticsearch Tutorial for Beginners
2:03:37
ProgrammingKnowledge
Рет қаралды 184 М.
What is Elasticsearch?
9:53
IBM Technology
Рет қаралды 441 М.
Про Elastic Stack за 15 минут.
15:23
ИТ-Видео
Рет қаралды 69 М.
Elasticsearch Deep Dive w/ a Ex-Meta Senior Manager
44:03
Hello Interview - SWE Interview Preparation
Рет қаралды 40 М.