Skip to content

Commit

Permalink
Added endgame-* index and new heading 3 Elastic Endpoint SMP. (elasti…
Browse files Browse the repository at this point in the history
  • Loading branch information
jmikell821 committed Nov 27, 2019
1 parent fc94297 commit 3aca050
Showing 1 changed file with 7 additions and 2 deletions.
9 changes: 7 additions & 2 deletions docs/siem/index.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ Kibana provides step-by-step instructions to help you add data. The
detailed information and instructions.

[float]
=== {Beats}
=== {Beats}

https://www.elastic.co/products/beats/auditbeat[{auditbeat}],
https://www.elastic.co/products/beats/filebeat[{filebeat}],
Expand All @@ -33,9 +33,14 @@ https://www.elastic.co/products/beats/packetbeat[{packetbeat}]
send security events and other data to Elasticsearch.

The default index patterns for SIEM events are `auditbeat-*`, `winlogbeat-*`,
`filebeat-*`, and `packetbeat-*``. You can change the default index patterns in
`filebeat-*`, `endgame-*`, and `packetbeat-*``. You can change the default index patterns in
*Kibana > Management > Advanced Settings > siem:defaultIndex*.

[float]
=== Elastic Endpoint Sensor Management Platform

The Elastic Endpoint Sensor Management Platform (SMP) ships host and network events directly to the SIEM application, and is fully ECS compliant.

[float]
=== Elastic Common Schema (ECS) for normalizing data

Expand Down

0 comments on commit 3aca050

Please sign in to comment.