To access material, start machines and answer questions login.
In a modern Security Operations Center (), detection starts with data, but raw logs alone provide limited value without the ability to centralize, search, and visualize them at scale. The Elastic Stack enables security teams to ingest massive volumes of data and transform them into actionable insights. In this room, you'll explore Elastic's core architecture and get hands-on experience building a lab to ingest, search, and investigate log data from multiple sources.
Learning Objectives
- Understand the core components of the Elastic Stack
- Install and configure an Elastic Stack deployment
- Ingest, parse, and search log data from multiple sources
- Build dashboards and visualizations to analyze log data
Prerequisites
Some familiarity with the command line, concepts, and log analysis is recommended. However, all required commands and necessary information are provided in the walkthrough:
- Elastic Stack: The Basics for an overview of Elastic architecture, running queries, and creating visualizations
Machine Access
Click the Start Machine button below. The machine will start in Split-Screen mode, and you will have access to all necessary files in the /home/ubuntu/Downloads directory.
We recommend switching to Full Screen mode for a more immersive experience. This provides a larger workspace, making it easier to manage the terminal and browser as you progress through the room. If your side menu is stuck in full screen, please enter and exit to fix the issue.
Set up your virtual environment
I understand the learning objectives and am ready to build a SOC lab with Elastic!
Ready to learn Cyber Security?
The Elastic: Setting up a SOC Lab room is only available for premium users. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.
Already have an account? Log in