Summary
We built on the hunting lab that you created in the previous chapter in preparation for wading into learning how to perform searches and create visualizations and dashboards in Kibana.
In this chapter, you learned how to configure the collection agents and tools you installed in Chapter 4, Building Your Hunting Lab – Part 1 and Chapter 5, Building Your Hunting Lab – Part 2. Additionally, we covered the configuration of Fleet used to manage Elastic Agent. This knowledge will help you not only maintain and adapt your collection policies going forward in your lab, but also in production environments.
In the next chapter, we'll be learning how to use the Kibana Query Language (KQL) and the Event Query Language (EQL) to perform focused searches on our data.