Summary
In this chapter, we explored the Discover, Visualize, and Dashboard apps and learned multiple query languages. We created saved searches and then built visualizations and dashboards off of those saved searches.
You have gained the skills that are needed to search for events using the Discover app, write multiple types of queries (such as Lucene, KQL, and EQL), and create visualizations that will facilitate threat hunting.
In the next chapter, we'll learn about the Elastic Security app, and in the chapter after that, we'll be using the lessons learned in this chapter to hunt through simulated threat data.