What to make of data from all over?
22
Domain
Data Sources
Timing
Collection Methods
Network
NetFlow, PCAP, Zeek
Real-time, Packet-based
Filebeat, Packetbeat, Logstash NetFlow module
Application
Log
Real-time, Event-based
Filebeat Logstash
Cloud
API, Log
Real-time, Event-based
Beats Logstash
Host
Signature Alert, System State
Real-time, Asynchronous
Auditbeat, Winlogbeat, Filebeat Osquery module
Active
Scanning
User-driven, Asynchronous
Vulnerability scanners