Security threat analysis points for enterprise with ossHibino Hisashi
The document provides an overview of using Elastic Stack to analyze security threats through log data. It discusses collecting logs from various systems like Windows event logs, Linux audit logs, proxy logs, and correlating the logs. It emphasizes the importance of visualizing log data through graphs to detect anomalies and targeted external threats on servers as well as potential internal threats and information leaks. Winlogbeat and Filebeat modules make it easier to collect and parse logs without needing to modify them. Timeline and worksheets can also help identify misconduct by correlating logins with work hours.
21. 21
次期メジャーバージョンの8系から気をつけて...
[2020-02-
04T03:42:38,051][WARN ][logstash.outputs.elasticsearch][X
XX] DEPRECATION WARNING: Connecting to an OSS
distribution of Elasticsearch using the default distribution of
Logstash will stop working in Logstash 8.0.0. Please upgrade
to the default distribution of Elasticsearch, or use the OSS
distribution of Logstash {:url=>"https:// search-test-hoge.ap-
northeast-1.es.amazonaws.com:443/"}
AmazonESはOSS版Elasticsearchで構成されているため、LogstashもOSS版にしないと出力できなくなる。
23. 23
Open Distro for Elasticsearchとは
2019年3月に突如AWSがGitHub公開した別ディストリビューションのElasticsearchです!
【参考】新登場 – Open Distro for Elasticsearch
https://aws.amazon.com/jp/blogs/news/new-open-distro-for-elasticsearch/
じゃないよ!