Elasticsearch
We learned a lot about the functionality of Elasticsearch in Chapter 2. Namely, we discovered that it’s an enhanced type of database for enriched SIEM information. Now that we’ve set up our Kali Purple operating system within a virtual machine (VM), what do you say we go out and grab ourselves a real copy of this famed Elasticsearch, and then install and configure it so that we can play with it?
Feel free to go back to Chapter 3 if you need a refresher on how to get up and running, as well as log in. Otherwise, start by opening VirtualBox and selecting the Kali Purple VM we’ve created. Assuming you’ve done no renegade independent adjustments on your own since then, that should be the only VM you have available to select at this time. Highlight it and click the Start button near the top-right of the window. Enter the credentials you created in Chapter 3 for your non-administrative account and click Log In to get yourself into the Kali Purple...