Elastic solutions
Elastic uses the concept of solutions to organize ways that the stack can be used to solve use cases. The three solutions are as follows:
- Search: Enterprise Search
- Observe: Health and performance logging and metrics
- Security: Threat detection and response
We're going to be focused on the Security solution. That said, now that you have Kibana running, you can explore the Enterprise Search and Observability solutions. They are all available and have no cost. The very basic data that we have sent into the stack so far won't populate much, if any, of those solutions; so beyond being able to see the interface, there isn't much else to do.
As the Security solution has access to endpoint data, complete visibility into the collections apparatus and capabilities, and the ability to modify the protective posture of the environment, Elastic has required extensive configuration to ensure that the data is secure. We're going to go over that...