5 ms·
Seems like the natural evolution of the already popular ELK stack. I hope they add popular siem features like archiving, alerting, central configuration managem
by pingec 7y ago
Seems like the natural evolution of the already popular ELK stack. I hope they add popular siem features like archiving, alerting, central configuration management etc. I'll stick with graylog for now.
- jcims 7y agoI grew up on Splunk and can’t seem to figure out how to get the same level of aggregations and analysis of ad hoc data out of ELK. Sometimes I think I’d be better served with Jupyter and Spark or similar.
- vetrom 7y agoThats because most of the ElasticSearch data model is materialized indexes. You need to reindex (or use one of the other ops which amounts to building a composite index) to create different aggregates. Otherwise you need to use constructed JSON queries instead of adhoc lucene string searches to build the more complicated searches on those fields. Kibana provides tools that can help visualize building those if you don't do it from scratch, but its definitely a different workflow than Splunk or something implementing a more traditional query language.
- strictnein 7y agoSplunk is kind of a magical beast, where you can throw lots of junk in and get meaningful results out. ELK wants you to massage the data more first.