# Dec 25th, 2022: \[EN\] How to build a cluster for Elastic Security: Best practices for creating and generating security data in Elastic Cloud

**URL:** <https://discuss.elastic.co/t/dec-25th-2022-en-how-to-build-a-cluster-for-elastic-security-best-practices-for-creating-and-generating-security-data-in-elastic-cloud/321832>\
**Category:** Advent Calendar\
**Created:** [December 24, 2022, 11:00pm UTC](https://discuss.elastic.co/t/dec-25th-2022-en-how-to-build-a-cluster-for-elastic-security-best-practices-for-creating-and-generating-security-data-in-elastic-cloud/321832 "2022-12-24T23:00:00Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tanisha\_L\_Turner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tanisha_l_turner/32/114586_2.png) [@Tanisha\_L\_Turner](https://discuss.elastic.co/u/Tanisha_L_Turner)\
**Post date:** [December 24, 2022, 11:00pm UTC](https://discuss.elastic.co/t/dec-25th-2022-en-how-to-build-a-cluster-for-elastic-security-best-practices-for-creating-and-generating-security-data-in-elastic-cloud/321832/1 "2022-12-24T23:00:00Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/9/a/9a917f6708fb693ba59ba897d5f9da6161886547.jpeg)

**Introduction**

When building a cluster for [Elastic Security](https://www.elastic.co/guide/en/security/current/es-overview.html#es-overview) in Elastic Cloud, there are different methods to [add security data](https://www.elastic.co/guide/en/security/current/ingest-data.html). The easiest method for adding and shipping security data to Elastic Cloud is with using the [Elastic Agent Integration](https://docs.elastic.co/en/integrations#elastic-integrations).

There are a number of factors that need to be considered prior to creation and building a cluster for Elastic Security:

- ✅ Determine the type of data that is best suited for the use case scenario - Data architecture and design

- ✅ Check if the host environment has sufficient resources for allocation - Depending on the type of data and analytics CPU and storage capacity may require scaling adjustments

- ✅ Verify and check current and existing apps for compatibility to identify and resolve any potential conflicts - There are a number of security integration apps that are viable and used for SIEM environments

- ✅ Identify any external third party apps will be needed for integration and verify any existing applications will integrate and identify any potential conflicts

- ✅ Determine how the data will be used and the expected results - The data generated will display results based on the type of visualizations, dashboards, metrics, and based on the use case scenario, can be used for report gathering, monitoring, and analytics

**How to Add Integrations and generate security data?**

1. **[Create a deployment in Elastic Cloud](https://www.elastic.co/guide/en/cloud/current/ec-create-deployment.html#ec-create-deployment)** ([Free 14 day trial for Elastic Cloud](https://cloud.elastic.co/registration?elektra=guide-welcome-cta))

- I created a deployment `TTesting8.5.3` with a 1 GB Kibana instance, and a 1 GB Machine Learning Instance for [Anomaly Detection of ML jobs](https://www.elastic.co/guide/en/security/8.5/machine-learning.html), detection rules, and alerts.

 ![Screen Shot 2022-12-23 at 10.59.12 PM](https://us1.discourse-cdn.com/elastic/original/3X/a/1/a15b95023b94a98a15873c996c9a43148752f6c7.jpeg)

1. On the Kibana Home Screen Select --\> **Add Integrations**

 ![Screen Shot 2022-12-23 at 10.33.25 PM](https://us1.discourse-cdn.com/elastic/original/3X/b/2/b2ca022ff1690932ed4fa714447ea19b5421397e.jpeg)

1. There will be a number of Integrations displayed. You can also Filter for the type of Integrations that you want to see. In this case, I filtered for Security integrations

 ![Screen Shot 2022-12-23 at 11.10.20 PM](https://us1.discourse-cdn.com/elastic/original/3X/a/a/aa28f4f8e5c5eb4e5686c2b6328e46caae6dd36a.jpeg)

1. Select the type of Elastic Agent integrations that you want to add. In this scenario, I will select **Network Capture** to capture network traffic from various protocols. I selected new hosts and named the policy `networktrafficagencypolicy3debian`

 ![Screen Shot 2022-12-24 at 12.04.10 AM](https://us1.discourse-cdn.com/elastic/original/3X/4/8/48f6b411cc4d2a0dd8cfe131ea7612e811bdc74f.jpeg)

1. The pop out window will display and Select ---\> **Add Elastic Agent to your hosts**. A fly out window will provide options to add Elastic Agent based on the OS. In this scenario, I selected the Linux/Tar option. Copy the commands from the OS options that aligns with your host.

 ![Screen Shot 2022-12-24 at 12.36.47 AM](https://us1.discourse-cdn.com/elastic/original/3X/d/9/d9857c132df81d91f538bed27075f254f2c08492.jpeg)

\*_Note: There can only be one Elastic Agent per host environment. If you want to install on multiple OS environments, a recommendation is to use virtual machines or containers._  
_I have Elastic Agent installed on both Linux and Windows environments in Parallels Desktop on MacOS_

1. Open a `Terminal` window for `command line` and paste the contents. In this scenario, I opened a Terminal Window on Debian GNU Linux 11.3 hosted in my Parallels Deskstop Virtual Environment on MacOS and pasted the contents on command line.

 ![Screen Shot 2022-12-24 at 12.34.39 AM](https://us1.discourse-cdn.com/elastic/original/3X/3/7/37a446f88dcb2f1696ea6240286b074093b8ab67.jpeg)

1. Go back to your Elastic Cloud deployment to confirm if the Elastic Agent is installed and data is being shipped

 ![Screen Shot 2022-12-24 at 12.20.34 AM](https://us1.discourse-cdn.com/elastic/original/3X/1/6/164b9a5cd29855f2af1ead8153c0be1db31077ba.jpeg)

1. To view the visualization dashboard for this integration. Select from the left panel  
Under Kibana Section **Analytics --\> Dashboard**. You will be provided a list of various dashboard option views associated with this visualization.

 ![Screen Shot 2022-12-24 at 12.52.56 AM](https://us1.discourse-cdn.com/elastic/original/3X/9/b/9b5b5bd1a20e97275b17ab33a194d45001b2eb3b.png)

In this scenario, I selected **Network Packet Capture Overview** to get a comprehensive view of traffic latency, response times, of the different transaction types on all hosts with this integration:

 ![Screen Shot 2022-12-24 at 12.53.22 AM](https://us1.discourse-cdn.com/elastic/original/3X/b/9/b9966f9c3c1fa8089e0561c7265ac27f1208a6f0.png)

**Network Packet Capture Overview on all hosts**

 ![Screen Shot 2022-12-24 at 12.54.33 AM](https://us1.discourse-cdn.com/elastic/original/3X/7/2/72a6f7bf7a7ed1f0e233f4a0ac9039a6db8f0a0f.jpeg)

**Conclusion**  
The Elastic Agent Integrations is an effective, time saving method for adding security data. The variety of options to ship data from third party apps helps to reduce manual setup configuration tasks. By implementing best practices for building and ingesting data, the security solution can be a viable option for security analytics, detection, and monitoring in both production and non-production environments.

Want to practice and test out Elastic Integrations and explore Security data? Please feel free to sign up for a [14 day Elastic Cloud trial](https://cloud.elastic.co/registration?elektra=guide-welcome-cta), which comes with an option to add sample data and Prebuilt Detection rules.

![image](https://us1.discourse-cdn.com/elastic/original/3X/c/d/cd585d03c2badc9eb8312f9bacb7a69f76e0013d.jpeg)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 21, 2023, 11:00pm UTC](https://discuss.elastic.co/t/dec-25th-2022-en-how-to-build-a-cluster-for-elastic-security-best-practices-for-creating-and-generating-security-data-in-elastic-cloud/321832/2 "2023-01-21T23:00:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
