Agents and monitoring
There are a couple of prominent additional applications that are associated with the ELK stack. They are the open source Beats and the commercially available X-Pack. It is the addition of these two components that transitions the ELK stack into a fully functioning SIEM. Together, they provide data collection and shipping, alerting and notification, machine learning for detecting hidden anomalous behavior, and automated reporting.
Beats
Beats is a group of data collection and transportation agents. These are sometimes referred to as data shippers. They are lightweight – miniature – applications that are installed on endpoints so that they include personal computers, servers, and other network devices for the sole purpose of collecting data to ship off to Elasticsearch and Logstash for further processing in real time. Beats collect operational data from the devices they are installed on. It gets it from different sources, including logs and network...