Lesson 2 of 10
SIEM Deep Dive - Splunk & ELK
Splunk
index=windows EventCode=4625 | stats count by src_ip index=firewall action=blocked | top src_ip
ELK
- Filebeat → Logstash → Elasticsearch → Kibana
- Creating detections
Lesson 2 of 10
index=windows EventCode=4625 | stats count by src_ip index=firewall action=blocked | top src_ip