Skip to main content
Back to all walkthroughs
Room Icon

Elastic Stack: The Basics

Premium room

Understand how SOC analysts use the Elastic Stack (ELK) for log investigations.

medium

180 min

73,112

User profile photo.
User profile photo.
User profile photo.

To access material, start machines and answer questions login.

In this room, we will learn how the Elastic Stack () can be used for log analysis and investigations. Although ELK is not a traditional , many teams use it like one because of its data searching and visualizing capability. We will explore how the components of ELK and learn how log analysis can be performed through it. We will also explore creating visualizations and dashboards in ELK. 

Learning Objectives

This room has the following learning objectives:

  • Understand the components of ELK and their use in SOC
  • Explore the different features of ELK 
  • Learn to search and filter data in ELK
  • Investigate logs to identify anomalies
  • Familiarize with creating visualizations and dashboards in ELK
Answer the questions below

I am all set!