How does your organization detect and respond to cyber threats? Learn how the latest security capabilities in the Elastic Stack enable interactive exploration and automated analysis with speed and at scale.
5. Elastic Common Schema (ECS)
Normalize data to streamline analysis
• Defines a common set of fields and
objects to ingest data into Elasticsearch
• Enables cross-source analysis of diverse
data
• Designed to be extensible
• ECS is in GA and is being adopted
throughout the Elastic Stack
• Contributions & feedback welcome at
https://github.com/elastic/ecs
7. Elastic SIEM
A SIEM for Elastic Stack users everywhere
Elastic SIEM app
Elastic Common
Schema (ECS)
Network & host
data integrations
Kibana
Visualize your Elasticsearch data
and navigate the Elastic Stack
Elasticsearch
A distributed, RESTful search
and analytics engine
Beats
Lightweight data shippers
Logstash
A server-side data
processing pipeline
Elastic &
community
security
content
8. Elastic SIEM app
Triage alerts, or hunt for threats
All at the speed of thought
Analyst-friendly experience for
investigating security alerts
• Time-ordered events
• Drag-and-drop filtering
• Multi-index search
• Annotations, comments
• Formatted event views
• Persistent forensic data storage
17. Community
" Cloud platforms &
applications
" Network sources
" Host sources
" User activity sources
" SIEMs & centralized
security data stores
Security orchestration,
automation, response
Security incident
response
General ticket & case
management
Consulting
Education & training
Internal context
External context
Elastic SIEM Ecosystem
These are just some of our partners and community members. The presence of a vendor logo doesn’t imply a business relationship with Elastic.
18. Elastic Security Analytics Journey
Elastic Confidential Information - Roadmap information provided on this slide is an overview of overall direction and nothing is committed.
Threat Intelligence Integration, User Analysis
SIEM Detection Rules, More Data Sources
Dedicated SIEM App, SOC Workflow
Security Event Collection, Visualization, Dashboards
Elastic Common Schema (ECS)