3 ms·
That assumes they have bandwidth graphs. And sure, ES generates a lot of logs, but have you ever tried using them to investigate an exposure like this? Unless t
by resfirestar 7y ago
That assumes they have bandwidth graphs. And sure, ES generates a lot of logs, but have you ever tried using them to investigate an exposure like this? Unless the “xpack.security” module is on (off by default), it’s nothing useful.
- ryanlol 7y agoLinux itself gives you decent data from procfs (see /sbin/ifconfig, shows you data transfer in/out per adapter), you can just compare data transfer from the server to any of the boxes that are supposed to connected to. I can’t imagine that even MS would be running ES on windows, although then you’d probably have even more data available.