Chapter 4: Building Your Hunting Lab – Part 1
Now that we've gotten a lot of the theory and introductions out of the way, let's roll up our sleeves and build our hunting lab. The lab is where we'll be generating, collecting, ingesting, and analyzing events with the Elastic Stack.
Keeping with the same process that we have used in previous chapters, we'll use this chapter to build the host components, and in Chapter 6, Data Collection with Beats and Elastic Agent, we will install and configure them on the victim machine. While we could build and configure at the same time, in my opinion, when building and learning from the ground up, it's best to do things in stages.
In this chapter, we'll go through the following topics:
- Your lab architecture
- Building an Elastic machine