Summary
In this chapter, we learned about the genealogy of Kali Linux and began to unpack one of the most popular toolsets offered by the Purple variant of that OS. We started to delve deeply into the Elastic Stack, sometimes called the ELK stack, as that will become one of the primary focal points of this book, being the core of Kali Purple. We gained a healthy understanding of how Elasticsearch and Logstash work with data, from ingesting it to enriching it to aggregating it. We also saw how this data can be presented visually through Kibana.
After thoroughly examining how the ELK stack handles data, we started to examine the original data sources and how we glean data from there through Beats and pass it on to Elasticsearch, usually through Logstash as an intermediate stop, but not always. We studied the difference between sending data directly to Elasticsearch versus Logstash. We also peeked at the commercial component of the ELK stack, X-Pack, and were able to see how much of...