Using ES|QL in Kibana to Queries DShield Honeypot Logs, (Thu, Feb 20th)

SANS Internet Storm Center, InfoCON: green 2025-02-20

Summary:

With the Elastic released of version 8.17.0, it included "The technical preview of new MATCH and query string (QSTR) functions in ES|QL makes log searches easier and more intuitive."[1] With this released, I started exploring some of the many options available with ES|QL in Kibana [2], enabled by default, to do various types of queries to quickly summarize data, outside of the default or custom dashboards.

Link:

https://isc.sans.edu/diary/rss/31704

From feeds:

Intel Hub ยป T01 - SANS Internet Storm Center, InfoCON: green

Tags:

Date tagged:

02/20/2025, 07:08

Date published:

02/19/2025, 21:06