Network
Clicking on the Network tab will take you to an overview of the network data that is provided by the endpoints sending data into our Elastic Stack.
Similar to the Hosts section, there are protocol sections to allow you to review the more common network protocols, such as DNS, HTTP, and TLS. Flows are display data that doesn't fall into a parsed protocol, but is still recorded by Packetbeat.
Also, like the Hosts tab, you'll notice an External alerts section. This is where third-party network security solutions would report observations, such as Zeek or Suricata:
Figure 8.52 – Network overview of the Security solution
In this section, we introduced you to the Network section of the Security solution. Next, we'll explore Timelines, which is a powerful searching feature from within the Security solution.