Setting up Fleet Server
In our lab, we will be collecting telemetry from multiple endpoints. To enable this, we will install Elastic Agent on any system we want to collect data from. In larger deployments, agents can get deployed to hundreds or even thousands of endpoints and each of these endpoints can have different data collection requirements. Managing these agents can become complicated as the number and diversity of installed agents increase. Fleet Server is a component of the Elastic Stack that attempts to simplify agent management.
From Kibana, we can create different agent policies, which define what data should be collected, apply those policies to different endpoints, and even uninstall Elastic from these endpoints if we need to. This capability is extremely powerful, especially in larger environments with many endpoints.
We will use Fleet to manage the endpoints that we’ll connect to our detection lab. The following section details how to install Fleet Server...