Module 27 Working with Network Security Data Flashcards
What are the core elements for ELK
Elasticsearch, Logstash, Kibana and Beats
What is Kibana
Provides a graphical interface to data that is compiled by Elasticsearch
What is beats
Series of software plugins that send diff types of data to the elasticsearch data stores
What is logstash
Enables collection of network data into data indexes that can be searched by elasticsearch
What is Elasticsearch
An open-core platform for searching and analyzing an org data in near real time
What is ELK
To reduce Data, ELK identifies the volume of network data, shrinks it down, only the relevant stuff
What is data normalizaiton?
Process of combining data from a number of sources into a common format.
Why is data archiving important?
Retaining NSM data is not feasbile, Sguil alert data can be retained for 30 days.