SIEM Flashcards
Elastic Search Components
Logstash
Kibana
Beats
What is logstash?
Ingest pipeline that enriches the data.
What is Kibana
Visualization tool
What are beats?
Lightweight single purpose data shippers
What is Splunk?
Used for collecting, normalizing, aggregating, and analyzing a lot of data.
Maybe in real time.
What are the types of forwarders in Splunk?
Universal forwarder
Heavy forwarder
Light forwarder
What is a universal forwarder?
Does not even parse data, just literally forwards it to the next thing.
What is a heavy forwarder?
Combination of a universal forwarder and an indexer. FOrwards, indexes, and searches.
What is a light forwarder?
Old
What is an Indexer in Splunk?
Index incoming data and searches it.
What is a splunk dashboard
Collections of search queries. Can be updated in real time.
What is a splunk app?
Prepackaged frontend solutions. lots of dashboards.
What is netflow?
A feature that allows network administrators to monitor traffic.
what is a netflow exporter?
Sends data
What is a netflow collector?
Receives netflow data