Security Analytics Using ^^^ Stack Abhishek Bhuyan
ELKB Stack
Disclaimer This is more of demo session than slides...
Elasticsearch ● Distributed and Analytics Engine ○ Query anything - structured, unstructured, geo, metric ○ Analyze - Explore trends and patterns ○ RESTfulAPI ○ Schema Free, JSON Documents ○ Fast and Horizontally Scalable
Logstash ● Data Processing Pipeline ○ Ingest Data, Process and Output ■ Ingest Data of many sources (Input Plugins) ■ Parse & Transform data on the fly (Filter Plugins) ■ Change Data Representations (Codec Plugins) ■ Output data to many forms (Output Plugins)
Beats ● Lightweight Data Shippers ○ Data Gathering ■ Filebeat ■ Metricbeat ■ Packetbeat ■ Winlogbeat ■ Heartbeat
Kibana ● Explore, Visualise, Discover Data ○ Interactive Visualization ○ Custom Dashboards
Evolution of Cyber Threats
Evolution of Cyber Threats
What is Analytics? ● Data Driven approach for analyzing logs ● Ask the right question and then figure out what data you need to answer it ○ Helps in modeling your data ○ Helps in choosing the technology or tools you want to use
Let’s Demo
“The goal is to turn data into information, and information into insight.” – Carly Fiorina, former CEO, Hewlett-Packard Co.

Security Analytics using ELK stack

  • 1.
    Security Analytics Using^^^ Stack Abhishek Bhuyan
  • 2.
  • 3.
    Disclaimer This is moreof demo session than slides...
  • 4.
    Elasticsearch ● Distributed andAnalytics Engine ○ Query anything - structured, unstructured, geo, metric ○ Analyze - Explore trends and patterns ○ RESTfulAPI ○ Schema Free, JSON Documents ○ Fast and Horizontally Scalable
  • 5.
    Logstash ● Data ProcessingPipeline ○ Ingest Data, Process and Output ■ Ingest Data of many sources (Input Plugins) ■ Parse & Transform data on the fly (Filter Plugins) ■ Change Data Representations (Codec Plugins) ■ Output data to many forms (Output Plugins)
  • 6.
    Beats ● Lightweight DataShippers ○ Data Gathering ■ Filebeat ■ Metricbeat ■ Packetbeat ■ Winlogbeat ■ Heartbeat
  • 7.
    Kibana ● Explore, Visualise,Discover Data ○ Interactive Visualization ○ Custom Dashboards
  • 8.
  • 9.
  • 10.
    What is Analytics? ●Data Driven approach for analyzing logs ● Ask the right question and then figure out what data you need to answer it ○ Helps in modeling your data ○ Helps in choosing the technology or tools you want to use
  • 11.
  • 12.
    “The goal isto turn data into information, and information into insight.” – Carly Fiorina, former CEO, Hewlett-Packard Co.