Thanks for the answer. It cleared a lot of things in my head.
One more question:
I make my own custom schema in terms of event fields. So do i have to use the ECS, or few of the ECS's fields, or i can make my own visualizations in Kibana with custom fields?
There are certainly advantaged of mapping to ECS If you want to take advantage of the security analytics applications within Kibana and some of the default detections and other features etc.
But it's not required if you want to do everything custom.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.