August 2025
Intermediate to advanced
344 pages
8h 34m
English
Once you’ve collected logs from devices across your environment, you might want to standardize them further by adding, removing, or renaming fields so they’re easier for security analysts to find. If done properly, standardization could also enable you to feed your logs into automated response tools and machine learning solutions, allowing you to automate aspects of your security operations. Many tools exist to perform this kind of processing, but in this part of the book, we’ll focus on an Elastic tool called Logstash. Chapter 8 introduces the input and output plug-ins you can use to craft your data transformation pipeline, and Chapter 9 discusses Logstash’s transformation filters, which ...
Read now
Unlock full access