logo

Security operations: Cloud monitoring and detection with Elastic Security

ID: eb09a3cd-80e0-5f5a-913f-fbf58462139a

STIX ID: report--eb09a3cd-80e0-5f5a-913f-fbf58462139a

Feed Name: Elastic Security Labs

Date Published: 2022-11-30

Date Updated: 2026-04-27

...
...

Elastic details how its Security platform ingests and normalizes cloud logs (AWS, Okta, etc.) using Filebeat and ECS, and provides free detection rules and ML jobs to identify suspicious behaviors. Through simulated AWS and Okta attack scenarios—such as disabling logging/recording, harvesting secrets, and weakening access controls—the post shows how detections fire, how analysts triage via Timeline, and how exceptions and threshold rules reduce noise and surface meaningful alerts, helping teams monitor cloud environments more effectively.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.