The Elastic Stack
Another open source option for a SIEM is the Elastic Stack (or the ELK Stack, as it is commonly known). The Elastic Stack is a combination of three tools in one. The open source tools Elasticsearch, Logstash, and Kibana are combined to provide threat hunters with an open source platform that ingests data and then transforms it into a format that can be viewed and analyzed via the Kibana GUI. This provides the ability for threat hunters to visualize log data from multiple systems at once. The Elastic Stack is built into a number of different open source security tools, including the aforementioned Security Onion. The Elastic Stack can also be configured as a standalone SIEM solution, with tools such as Winlogbeat, which forwards ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access