1.使用path_hierarchy tokenizer进行层级搜索
https://spinscale.de/posts/2021-03-17-search-hierarchies-using-elasticsearch-path-hierarchy-tokenizer.html
2.配置Filebeat 数据到不同的索引
https://alexmarquardt.com/2021/03/15/driving-filebeat-data-into-separate-indices-uses-legacy-index-templates/
3.使用EQL检测内网漫游
https://www.elastic.co/cn/blog/hunting-for-lateral-movement-using-event-query-language
[尊重社区原创,转载请保留或注明出处]
本文地址:http://elasticsearch.cn/article/14273
本文地址:http://elasticsearch.cn/article/14273