Главная
Study mode:
on
1
Intro
2
AN ELSA TIMELINE
3
WHY SPHINX?
4
WHY ELSA?
5
INTRODUCING ELSA 2.0
6
GOALS OF ELSA 2.0
7
ELASTICSEARCH: EMBRACE THE HORROR
8
ELASTICSEARCH 2.X NOTEWORTHY FEATURES
9
ELASTICSEARCH IS NOT ELASTIC
10
FED ARCHITECTURE
11
SYSLOG-NG IMPROVEMENTS
12
CONTAINERS
13
ACTION STATUS
14
BRANCHED BREADCRUMB DATA MODEL
15
TRANSCRIPTS ARE NAVIGABLE HISTORY
16
TRANSCRIPT ACTION: SCOPE
17
TRANSCRIPT ACTION: PIVOT
18
TRANSCRIPT DATA MODEL
19
QUANTIFIABLE INVESTIGATION PERFORMANCE
20
FAVORITES
21
GROUPED HISTOGRAM
22
SANKEY
23
FORCE DIRECTED GRAPH
24
GEO COUNTRY MAP
25
ELSA 2.0 STATUS AND TIMELINE
Description:
Explore the evolution and capabilities of ELSA (Enterprise Log Search and Archive) in this conference talk from Security Onion Conference 2016. Dive into the reasons behind choosing Sphinx and ELSA, and discover the exciting features of ELSA 2.0. Learn about the integration with Elasticsearch, including its noteworthy features and architectural considerations. Examine improvements in syslog-ng, containerization, and the new branched breadcrumb data model. Gain insights into navigable transcript history, transcript actions like scope and pivot, and the quantifiable investigation performance. Discover visualization tools such as grouped histograms, Sankey diagrams, force-directed graphs, and geo country maps. Get an update on ELSA 2.0's status and timeline, equipping yourself with valuable knowledge for enhancing your security analysis capabilities.

Using ELSA for Fun & Profit

Security Onion
Add to list
0:00 / 0:00