Free

Getting Started with ELK Stack: Beats and Endpoint Agents

If you are using the Elastic ELK Stack as your SIEM, you need to know how to deploy and configure Beats and Endpoint Agents to forward your logs. In this part of our ELK Stack series, you will learn how to deploy and configure these tools and get hands-on in our virtual lab to apply what you’ve learned.
2
32
M
Time
intermediate
difficulty
3
ceu/cpe

Course Content

Course Description

If you will be using the Elastic ELK Stack as your SIEM, you need to know how to deploy and configure Beats and Endpoint Agents to forward your logs. In this part of our ELK Stack series, you will learn how to deploy and configure these tools and get hands-on in our virtual lab to apply what you’ve learned.

Who should take this course?

The target audience for this training is individuals who work in a Network Security role or Administration who may be interested in implementing the Elastic ELK stack into their environment. This training is also intended for entry-level SOC analysts who may be using ELK.

What are the prerequisites for this course?

This training assumes you have a foundational knowledge of TCP/IP networking, ports and protocols, and Linux and Windows fundamentals. It is also beneficial if you have taken the other courses in the ELK Stack series, particularly the course, "Getting Started with ELK Stack: Queries."

Why take this course?

What makes this course so beneficial is that you will learn what makes ELK Stack an affordable and flexible SIEM solution that can serve many use cases. In this course, you will get hands-on experience using ELK Stack as a SIEM and deploying a Beats and Endpoint Agents to forward logs, then querying them to check your work. After completing this course and other courses in the ELK Stack series, you will be prepared to take the capstone lab in this series, where you will use ELK to detect malicious activity in a realistic threat-hunting scenario. The ELK Stack courses are being released over time, so be sure to check back for them if you don't see them on the Cybrary platform right away.

What makes this course different from others?

By the end of this course, you should be able to:

  • Deploy and configure a Filebeats Agent for a Unix Host
  • Deploy and configure a Winlogbeats Agent for a Windows Host
  • Deploy and configure Endpoint Agents on both Windows and Linux
  • Query the forwarded logs to check your work
  • Your instructor, Skyler Gehman, is a Cyber Operations Specialist in the Army. He is a graduate of the Joint Cyber Analysis Course at the Navy's Center for Information Warfare and the Army's Cyber Center of Excellence for Offensive and Defensive Cyberspace Operations. He has also worked in the manufacturing of military electronics and weapons systems.

    This course is part of a Career Path:
    No items found.

    Instructed by

    Instructor
    Skyler Gehman

    In my job as a Defensive Network and Host Analyst, I deploy network security monitors (NSM’s) as well as host intrusion detection (HID) agents, and I monitor the health and security of enterprise networks in the DoD. I also perform forensic analysis of compromised host systems, as well as static and dynamic analysis of malware.

    I am a graduate of the DoD’s Joint Cyber Analysis Course (JCAC), where I learned the fundamentals of cybersecurity, as well as more advanced concepts like Offensive Cyber Operations, Digital Forensics, and Information Warfare. I then graduated from the US Army’s Cyber Operations Course, where I built upon the fundamentals taught in JCAC in several months of practical Offensive and Defensive cyber operations simulations. I earned my Security+ certification from Comptia in 2020 and completed the DoD Cyber Crime Center’s Defense and Counter Infiltration course in 2021. I am currently pursuing a degree in Cybersecurity and Information Assurance, as well as my CySA+, CASP+, and CEH certifications. I enjoy cybersecurity because of the openness and collaborative spirit of all of the professionals in this field. In cybersecurity, there is always more to learn, and always someone willing to teach it to you. It’s been very meaningful to me to have the opportunity to teach technical skills to new learners who can use that knowledge to better themselves, and those around them.

    I’m an avid science fiction fan, with some of my favorite books being Dune, Shadow of Ender, Neuromancer, and Heart of Darkness.

    Provider
    Cybrary Logo
    Certification Body
    Certificate of Completion

    Complete this entire course to earn a Getting Started with ELK Stack: Beats and Endpoint Agents Certificate of Completion