Network Security Monitoring
Steve Anson · 2019
Network security monitoring remains a vital component for incident response, threat hunting, and network security in general. This chapter focuses on network activity and explores the Elastic Stack and ways to integrate host-based data to provide enhanced visibility across the network. It examines the architecture for deployment of Security Onion in an enterprise and each of the major tools integrated into the platform. The chapter outlines basic skills to facilitate effective incident response for those situations where the critical data that reader need has not been conveniently placed into Elastic Stack or another analysis platform. The Elastic Stack provides an amazing platform to support incident response, but readers occasionally will need to access other data sources directly on a host or that otherwise have not been ingested into a centralized analysis platform. Web servers, *nix systems, and other applications store many of their logs in a text-based format.