The Discover app
The Discover app is the main view of your data stored in Elasticsearch. If you had no other solutions, visualizations, or dashboards, you could still explore all of your data with Discover.
Using Discover, we'll learn how to leverage the true strength of Kibana – filters. Raw searching capability is, of course, very powerful. However, in threat hunting, frequently, you don't exactly know what you're looking for, so simply blindly searching through data will result in suboptimal results (if any). Filters, as we'll discuss in more detail, allow you to surgically examine data to discover what's hidden inside.
Important note
The Discover app only shows the first 500 events for a search. This is for performance. We will use time selections and filters to uncover and zero in on the data of interest. You can't efficiently search through more than 500 events, so while it can be confusing (or frustrating) at first, this truly makes...