Webcast: Windows logging, Sysmon, and ELK
ID: 042de77b-946e-516d-8083-ab2158d21348
STIX ID: report--042de77b-946e-516d-8083-ab2158d21348
Feed Name: Black Hills Infosec Blog
This webcast and accompanying slides provide an instructional overview for getting Windows events out of Windows using Sysmon and into an ELK stack, covering components (Elasticsearch, Logstash, Kibana), Winlogbeat, HELK, log types, ingestion practices, and related tooling such as Sigma.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
