Lecture 4 pt. 6 Flashcards

1
Q

What is Kibana?

A

Kibana is a browser-based analytics and search dashboard for Elasticsearch.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is Logstash?

A

Logstash is a pipeline processing system that connects ‘inputs’ to ‘outputs’ with optional ‘filters’ in between.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is Elasticsearch?

A

Elasticsearch is a document-oriented full-text search engine.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does ELK stand for?

A

ELK stands for:
* Elasticsearch
* Logstash
* Kibana

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is Security Onion?

A

Security Onion is an open-source product that includes the ELK suite to provide SIEM functionality.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are two popular proprietary SIEM systems?

A

Two popular proprietary SIEM systems are:
* SolarWinds Security Event Manager
* Splunk Enterprise Security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is Squert?

A

Squert is a web application used to query and view event data stored in a Sguil database, such as IDS alert data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How is Sguil pronounced?

A

Sguil is pronounced ‘sgweel’.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is Sguil?

A

Sguil is an intuitive SIEM GUI that provides access to real-time events, session data, and raw packet captures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly