Elasticesearch and event correlation


(John Zhang) #1

Hi guys,

I am one newer for elasticesearch.

I am trying ElasticSearch +Kibana + Logstash for my security log
management, I also need do event correlation on this platform, like what
Simple Event Correlator (SEC, http://simple-evcorr.sourceforge.net/) do.

My question is:
How I do event correlation with ElasticSearch +Kibana + Logstash? Or Can I
make SEC work with ElasticSearch +Kibana + Logstash?

Any suggestion, comment will be highly appreciated!

Thanks!

Best regards,
John

--
You received this message because you are subscribed to the Google Groups "elasticsearch" group.
To unsubscribe from this group and stop receiving emails from it, send an email to elasticsearch+unsubscribe@googlegroups.com.
For more options, visit https://groups.google.com/groups/opt_out.


(Jason Weber) #2

John,
Same questions, did you ever figure anything out on this?

Jason

On Friday, June 7, 2013 4:35:22 AM UTC-4, John Zhang wrote:

Hi guys,

I am one newer for elasticesearch.

I am trying ElasticSearch +Kibana + Logstash for my security log
management, I also need do event correlation on this platform, like what
Simple Event Correlator (SEC, http://simple-evcorr.sourceforge.net/) do.

My question is:
How I do event correlation with ElasticSearch +Kibana + Logstash? Or Can
I make SEC work with ElasticSearch +Kibana + Logstash?

Any suggestion, comment will be highly appreciated!

Thanks!

Best regards,
John

--
You received this message because you are subscribed to the Google Groups "elasticsearch" group.
To unsubscribe from this group and stop receiving emails from it, send an email to elasticsearch+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/elasticsearch/b4d3f19f-534c-4f05-88e0-23770c4638fd%40googlegroups.com.
For more options, visit https://groups.google.com/groups/opt_out.


(system) #4