# New Here - Question

**URL:** <https://discuss.elastic.co/t/new-here-question/49609>\
**Category:** Elasticsearch\
**Created:** [May 10, 2016, 3:31am UTC](https://discuss.elastic.co/t/new-here-question/49609 "2016-05-10T03:31:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Locknet\_Ssmith](https://avatars.discourse-cdn.com/v4/letter/l/7bcc69/32.png) [@Locknet\_Ssmith](https://discuss.elastic.co/u/Locknet_Ssmith)\
**Post date:** [May 10, 2016, 3:31am UTC](https://discuss.elastic.co/t/new-here-question/49609/1 "2016-05-10T03:31:04Z")

</div>

Hey all - I learned of ELK recently while attending a SANS Institute webinar. It was mentioned in passing by the sponsor of the webcast, which was devoted to building a threat intelligence system from scratch.

So I'm investigating, but there is a lot of info, and I'm not sure where to start.

Basically our situation is that we monitor a high volume of managed firewalls. Part of that is to watch IPS, Anti-Virus, and Informational alerts that come to our team via email, all day, all night. We rotate shifts of people who are responsible for monitoring the mailbox, but also for pulling data out of those alerts when we notice patterns, trends, IoC's - things of concern. But we're currently just logging this information into a complex spreadsheet.

So that's our use case - any suggestions? Any direction on where a good place to start is?

Cheers

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 10, 2016, 7:00am UTC](https://discuss.elastic.co/t/new-here-question/49609/2 "2016-05-10T07:00:49Z")

</div>

That's a lot to answer, but it's possible with the stack. I'd start by pushing some data into ES (via Logstash) and then making sure you can get the basics of what you want (via Kibana).

If you have specific questions I am sure we can help more.

---

<div class="post-metadata">

**Author:** ![mainec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mainec/32/5557_2.png) [@mainec](https://discuss.elastic.co/u/mainec)\
**Post date:** [May 10, 2016, 8:45am UTC](https://discuss.elastic.co/t/new-here-question/49609/3 "2016-05-10T08:45:06Z")

</div>

> [@Locknet\_Ssmith](#):
>
> So I'm investigating, but there is a lot of info, and I'm not sure where to start.

One good point to start might be looking at what other people are doing with Logstash/ Beats/ Elasticsearch/ Kibana: [Elasticsearch customer success stories | Elastic Customers](https://www.elastic.co/use-cases)

Another thing would be to start searching for getting started stories about Logstash/ Beats/ Elasticsearch/ Kibana. One I found one [getting started post](http://blog.trifork.com/2014/01/28/using-logstash-elasticsearch-and-kibana-to-monitor-your-video-card-a-tutorial/) that looks decent but is already pretty dated.

Another option would be to start reading [the Elasticsearch Definitive Guide](https://www.elastic.co/guide/en/elasticsearch/guide/master/index.html)

Hope this helps,  
Isabel

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:52pm UTC](https://discuss.elastic.co/t/new-here-question/49609/4 "2017-07-05T22:52:51Z")

</div>


