Setting up ELK
At this point, you have two options. If you want to start small, you can follow these steps to deploy a raw ELK instance so that you can start querying plain Elasticsearch; alternatively, you can deploy the HELK, Roberto Rodriguez' open source hunting tool, which has more advanced capabilities. If you choose to do the latter, please jump to the The HELK – an open source tool by Roberto Rodriguez section.
In any case, you will need to download a Linux distro. I'm going to use Ubuntu 18.04 (https://releases.ubuntu.com/), but you can use any other you may like. Keep in mind that if you plan to install the HELK or move to it later, Roberto's tool is optimized for Ubuntu 18.04, Ubuntu 16, CentOS 7, and CentOS 8.
Once again, upload the distro's ISO to the ESXI databrowser and use it to create a new virtual machine. You will need to keep two things in mind:
- The ELK will receive a large amount of data, so give it a good amount of disk...