Analysis and Ingestion
Elastic is our security analysis platform, and it works best when we use it as one. It's a great place to search, correlate, and make sense of your data, rather than a data lake to pull data out of and analyze somewhere else. Because it isn't a data lake, the goal is to help you find what you need by searching within the analysis platform itself.
What we mean by "analysis platform"
An analysis platform is designed for asking questions of data right where it lives. Searching, correlating, alerting, visualizing, seeing anomalies, and spotting threats in the platform in near real time. The real value comes from the analysis you do inside it, rather than treating it as a staging area to grab data and move it out.
Putting it into practice
- Ingest with a purpose. The data you send to Elastic should support a logging, monitoring, correlation, or detection use case. High fidelity!
- Do your analysis in Elastic. Lean on searches, dashboards, machine learning, and detection rules to answer your questions right on the platform.
- Try not to use Elastic as an extraction layer. If you find yourself regularly exporting large amounts of raw data to analyze it in another tool, that's a likely sign the data would be happier somewhere built for it, like a data lake or object storage.
Need help with a search?
If you're trying to put together a specific, pointed search, and you aren't sure how to get there, reach out and we may be able help you build it.
To make that possible, it helps to come with a clear idea of what you're looking for. We can help you shape and refine a search, but open-ended, 'needle in a haystack' hunts are something you'll be best placed to drive yourself, since you should know your data and what you're after. The clearer the question, the more we may be able to help.
Contact Us
For any questions related to Elastic, email elastic@tamu.edu.