I’m testing ELK. So far it’s been very well sending logs from different platforms to elastic as well as indexing and creating views or graphs. My interest now is correlate event using all those logs entries. For example:
- because I received so many interfaces resets, I would like elastic to tell me that there is an issue on that router.
- or any security issue
- or any custom rule: if an user is login in many different devices in a short period, then that user is doing some thing out of plan.
Wondering if there is some tool or module like this in elastic.
Thank you vary much