KOREA
eGISEC
Q041
Data Leakage Prevention, DLP, Firewall, Zero Trust, Cloud Security, Cyber Security - Others
Elasticsearch is not just a simple No-SQL database or a conventional search engine; it is a comprehensive data platform that includes modules for collection, storage, and visualization. The Elastic platform enables analysis across various domains, from business analytics to integrated logging and security (SIEM + XDR) within a single platform.
1) Security Analysis (SIEM + XDR): It collects logs from different security solutions and utilizes them for integrated analysis and threat detection.
2) Logs/Performance (Metrics)/APM: It gathers logs from various devices and containers, employing machine learning for fault detection and statistical analysis.