I’m testing ELK. So far it’s been very well sending logs from different platforms to elastic as well as indexing and creating views or graphs. My interest now is correlate event using all those logs entries. For example:
because I received so many interfaces resets, I would like elastic to tell me that there is an issue on that router.
or any security issue
or any custom rule: if an user is login in many different devices in a short period, then that user is doing some thing out of plan.
Wondering if there is some tool or module like this in elastic.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.