Blog
Elastic-ing All the Things at BSidesLV 2017
By Guest Authors on Sun, 07/23/2017
Take five seconds to think: Which of the two scenarios is the worst as an incident responder? In the first one, you have to analyze terabytes of logs by grepping audits, Windows events, proxy, intrusion prevention systems and mail as you try to pivot, correlate and understand what the heck happened. In the second one, you don't have any logs at all!...