August 2025
Intermediate to advanced
344 pages
8h 34m
English
Data engineers must often figure out how to get data from remote hosts and into the security information event manager (SIEM). In this part of the book, we’ll cover tools that can run on the endpoints in your environment, collect logs from them, and forward these logs to a central location for storage or further processing. In Chapter 4, we’ll focus on the extraction of logs from an organization’s endpoints and network using a tool called Filebeat. In Chapter 5, we’ll discuss the Windows event log and how you can mine this critical data source with Winlogbeat, a companion tool to Filebeat. To centrally manage the log collection agents running on devices across your environment, you might choose to use ...
Read now
Unlock full access