SAINTCON 2019 - Daniel Dayley - Building your first SIEM with the Elastic Stack

preview_player
Показать описание
Correctly implemented, a Security Information and Event Manager (SIEM) is one of the best tools a blue team has in defending a network. This presentation covers introductory topics about SIEMs including what they are, why you need one, and the considerations that one must take in building one. We will discuss the types of events that a SIEM can detect We will discuss the core technologies involved and demonstrate the setup of a SIEM with ElasticSearch, Logstash, Kibana, RabbitMQ, ElastAlert, and Zeek.
Рекомендации по теме
Комментарии
Автор

New world record in speed demoing. And very good.

aboringfart
Автор

do we have any resource for the commands given here?

chiragbablani