Elasticsearch is one of the top open source SIEM out there. If you are a SOC engineer, ingesting and parsing logs to your SIEM is a key skill must have if you want to be able to build useful correlation rules. I will demo the basics of both using filebeat and logstash.
#dfir #blueteam #elasticsearch #logstash
Hope you like this video and please do like, share and subscribe as support for me doing more of this stuff and it is my pleasure to contribute back to the community with these channels.
Come follow me on other channels. Thanks a bunch!
LinkedIn: / cyber-nerd-b61014229
Twitter: / cyberne73816353
Facebook: / cyber-security-free-resource-103047895585535
Tumblr: / cyber-security-free-resource
Youtube: / @cybersecurityfreeresource278
Wordpress:https://cybersecurityfreeresource.wor...