Build a Powerful Home SIEM Lab Without Hassle! (Step by Step Guide)

Поделиться
HTML-код
  • Опубликовано: 20 янв 2025

Комментарии • 215

  • @levelupgoddess9289
    @levelupgoddess9289 9 месяцев назад +70

    I seriously need to start building my labs so I can get some “experience” under my belt. I need a tech job like yesterday.

    • @BJMolette
      @BJMolette 6 месяцев назад

      have you tried it?

    • @strand195
      @strand195 10 дней назад

      you get a tech job now ?

  • @limit_limitless9875
    @limit_limitless9875 11 месяцев назад +18

    As someone who was forced to change career paths and decided to go with IT you are a saint. I'll be sure to check out more videos. Thank you.

    • @SimplyCyber
      @SimplyCyber  11 месяцев назад +2

      Thx. Really great compliment. 💙

  • @valyntyno
    @valyntyno Год назад +48

    Probably the most concise, easy-to-follow home SOC lab setup I have seen so far. Kudos to Gerry Auger and to Abdullahi Ali for trying to make these highly marketable cybersecurity skills available to as many people as possible 🙏🏼

    • @SimplyCyber
      @SimplyCyber  Год назад +2

      that was the goal so NAILED IT! thx for the comment.

  • @nerminzlatanovic
    @nerminzlatanovic Год назад +12

    This is amazing! I’m going to add this to my Home Lab. I am already using Elastic in my SOC Analyst course with HTB. Thank you Dr. Auger for creating this video and sharing it!

  • @Zeropriest
    @Zeropriest 2 месяца назад +2

    Just wanted to say thank you for this and I will be creating my home lab as soon as I get home! I am trying to change my career path due to a loss in the family, I am passionate about protecting people and their information and I'm looking for all the help I can get to land a job. Thank you again for this awesome video!

  • @xCheddarB0b42x
    @xCheddarB0b42x 11 месяцев назад +140

    Employers are looking for candidates with hands-on experience. With home lab projects like this, you can build this experience at home outside of any enterprise environment. These activities are _more important_ than certifications or even degrees to Hiring Managers. People at three large companies each told me that. So get crackin

    • @seann9501
      @seann9501 5 месяцев назад +8

      Great advice; thank you

    • @ZacharyJansheski
      @ZacharyJansheski 7 дней назад +1

      I have so many projects its insane

    • @xCheddarB0b42x
      @xCheddarB0b42x 7 дней назад

      @@ZacharyJansheski Get busy, and good luck!

    • @LinuxNation.
      @LinuxNation. 2 дня назад

      Degrees are for moving up into higher positions. That's why people get them. Nobody gets a degree for "entry level" lol

  • @jasonp3484
    @jasonp3484 Год назад +8

    Great video with actual walk through visual instruction. The speed was great too, just knowledge and no fluff. Thank you. Subscribed

    • @SimplyCyber
      @SimplyCyber  Год назад +3

      The fluff videos kind of annoy me when I’m trying to get info so I’m not into it, despite the almighty algorithm

  • @Zikanshi-AG
    @Zikanshi-AG 11 месяцев назад +6

    This is awesome. I initially thought building a SIEM was actually never possible as an entry level SOC analyst. Thank you

  • @socrayhte
    @socrayhte 10 месяцев назад +6

    As a newbie in the SOC pathway, This is amazingly so simple to follow. A capital THANK YOU to you!

  • @phonogtaphologist
    @phonogtaphologist 5 месяцев назад +1

    A fun little way to test elastic defend agents, is run “atomic read team invoke” this can automatically run mitre attacks and you can check coverage and generate a bunch of alerts by running all tests. Image your vm before you run this though because it can mess things up when you run all the tests

  • @johnnytyler
    @johnnytyler 7 месяцев назад +4

    Patience and persistence are required. Careful, adherence to the instructions on the blogpost (link provided in the description). GA's overview is a high level, fast paced overview and Elastic's website layout has changed. Pay specific attention to the steps of adding the integration, installing the agent, and allowing the agent to be enrolled in Fleet. Very important to allow time for the agent to report the processes from the host to the Elastic Cloud. The results are not as fast as would seem in the video. Don't rush and keep trying! Thanks SC!

  • @sync_arts
    @sync_arts 11 месяцев назад +1

    It's near impossible that ELK and no-hassle fit in one sentence, thanks to you

  • @RB-sv7ru
    @RB-sv7ru Год назад +2

    Great video, love your content and the cyber threat briefing every morning. If anyone goes to integrate and none of them appear try signing out and back in and it works.

    • @SimplyCyber
      @SimplyCyber  Год назад +1

      Thank you for kind words and thx for tip on lab for others

  • @IoXxSekto36
    @IoXxSekto36 Год назад +4

    Loved the video definitely gonna do it when I get home and play with this one to. Thanks.

  • @TheReconstructionist-ok1yh
    @TheReconstructionist-ok1yh 5 месяцев назад

    I’m saving this vid for later but I just wanted to say thank you for putting my mind at ease with the intro. I was so overwhelmed just looking for a video that didn’t confuse me and told me exactly what I would be doing and how it would help me in building my cyber resume 👌🏿.

  • @everythingisalie3363
    @everythingisalie3363 17 дней назад

    Set this up! The hardest installing Kali Linux. This elastic stack is super user friendly and is a must have project on your portfolio.

  • @EdithJackson-d1n
    @EdithJackson-d1n 5 месяцев назад

    Thank you so much i remember doing this in class in our labs unfortunately I do not have access to these labs since I have graduated I think that sucks so you have opened up an opportunity to really keep abreast of my cybersecurity skills

  • @cybernaut644
    @cybernaut644 Год назад +8

    Thank you, Dr. Auger! Not sure if it was just me, but event.action: "nmap_scan" didn't fire any alerts. I replaced with process.name: "nmap" which triggered alerts and sent an email.

    • @abhinavkohli4293
      @abhinavkohli4293 6 месяцев назад

      i am still not getting an email even thought its showing on the dashboards

  • @kumarsiddappa6118
    @kumarsiddappa6118 9 месяцев назад +4

    not able to see nmap details , do we need to setup anything on ES to read

  • @nsfam6516
    @nsfam6516 Год назад +3

    This is exactly what i needed!

  • @coach_mill
    @coach_mill 4 дня назад

    This was awesome! It took some time setting up Kali Linux for me, not sure why, but once that was good the rest was a breeze! Thanks for the video!

  • @damianpodgorski6977
    @damianpodgorski6977 5 месяцев назад

    This video comes as a life saver for me! I am struggling to set up the elastic search on my linux vm so this will be my workaround 😊

  • @aloysiusiyke9676
    @aloysiusiyke9676 Месяц назад

    Thank you for this video Gerald. It was quite helpful. Thank you

  • @leemueller262
    @leemueller262 Год назад +2

    Fantastic! I know how I’ll be spending my weekend ❤

  • @emmanueldark993
    @emmanueldark993 11 месяцев назад +3

    Is anyone else having trouble setting that "Easy Lab" setup? On the "Install Elastic Agent" step I keep getting a stall and it states "Confirm agent enrollment" "Listening for agent" and there's an infinite scrolling wheel. I asked Chatgpt and it states my settings are probably misconfigured. If anyone has any suggestions or know the fix I will greatly appreciate it.

    • @ellatechie
      @ellatechie 12 дней назад

      same for me. Did you ever figure this out?

  • @Noir_Nouveau
    @Noir_Nouveau Год назад +1

    YOU ARE HIM Dr. G! Thanks!

  • @SKeee3
    @SKeee3 10 месяцев назад +1

    I followed every step to a T yet when I set up an email alert for "sudo -sv localhost" and ran the command line I get no email? Any tips on this?

    • @SimplyCyber
      @SimplyCyber  10 месяцев назад

      I also had an issue getting the email to fire. Suggest using a web book and validating the alert is firing to try and isolate the issue

  • @anguslou5640
    @anguslou5640 3 месяца назад +1

    Querying for Security Events in the Elastic SIEM, why there was no nmap or sudo events appear in the logs?

    • @brayan0742
      @brayan0742 3 месяца назад

      were you able to find a solution, I'm having the same issue.

    • @anguslou5640
      @anguslou5640 3 месяца назад

      @@brayan0742 I restarted the services and server. It appeared somehow. But after which, it is no longer appeared.

  • @IFBBPRO917
    @IFBBPRO917 10 месяцев назад +1

    This is my favorite RUclips channel!

    • @SimplyCyber
      @SimplyCyber  10 месяцев назад

      YASSSS!!!! Thank you for making my day! 💙

  • @adiscoverer2531
    @adiscoverer2531 3 дня назад +1

    Hey please im stuck in task 5 because i can't find "Logs" under observability, and the Elastic Cloud interface i'm using has lot of differences from the tutorial

  • @NicholasSouris
    @NicholasSouris Год назад +2

    First tutorial video I didn't have to fast forward thu

  • @kamalalleyne2197
    @kamalalleyne2197 11 месяцев назад

    how did you get the email to fire off at 9:13? In the video it looks like it was cut off and i didn't get to see exactly what you did.

    • @SimplyCyber
      @SimplyCyber  11 месяцев назад +1

      Thx for asking. I didn’t get the email and couldn’t troubleshoot it for the video. I thought I left a comment in there saying the email didn’t arrive but I guess it didn’t make the final vid. I would set it up w web hooks if I’m being practical since it’s more flexible and you would see it in practice (fire off a slack msg for example)

    • @RowanHawkins
      @RowanHawkins 11 месяцев назад

      Slack is awsome for this because its so easy to set up a slack instance and then view the alerts on say your phone.

  • @winnerdanny7
    @winnerdanny7 4 месяца назад +4

    NOTE: If you are using a Kali Linux VM on an Apple Silicon Mac, and you have the arm version of Kali installed, for installing the elastic agent you need to modify 'x86_64' to 'arm64' in the initial installation command you copy+paste to setup the elastic agent on the kali vm

    • @SimplyCyber
      @SimplyCyber  4 месяца назад +2

      Thx for the tip to help the people

    • @ellatechie
      @ellatechie 12 дней назад

      does this apply to Apple Sonoma as well?

    • @winnerdanny7
      @winnerdanny7 12 дней назад

      @ your macOS version doesn’t matter, its the type of chip that’s inside

  • @fastgidi
    @fastgidi 3 месяца назад

    I am just happy he's reading it off from a Medium Post written by a Nigerian! At least we're good at something too!

  • @Aries_Alpha
    @Aries_Alpha 2 месяца назад

    Kali vm connected and the nmap scans are successful but there is no log in kibana when I search for the nmap scans. Great tutorial well paced and informative I will get my issue resolved I hope.

  • @carol-lo
    @carol-lo Год назад

    Thanks so much! Dr Auger! Very nice and concise video!

  • @MD-mo9wb
    @MD-mo9wb 5 месяцев назад +3

    Saved to my SOC Analyst playlist to review later. I'm new so this went waaaay too fast lol.
    Edit: Literally playing this back on .75 lol

    • @Oluwabold
      @Oluwabold 4 месяца назад +1

      @@MD-mo9wb this was literally what i did, the guy was so fast that i had to slow him down by myself 😁

  • @Destrudo5359
    @Destrudo5359 28 дней назад +1

    did everything in the video, but can't find any logs after running nmap commands. Nothing shows in logs related to nmap. Any idea why?

    • @ellatechie
      @ellatechie 13 дней назад +1

      same here.

    • @trunksbrief4576
      @trunksbrief4576 12 дней назад +1

      @@ellatechieI had some trouble 2 weeks ago but decided to try it again and fortunately I got it.
      Did the agent install successfully?

    • @filippogiorgiorondo6932
      @filippogiorgiorondo6932 День назад

      did u solve?

    • @trunksbrief4576
      @trunksbrief4576 День назад

      @@Destrudo5359 did the elastic agent successfully connect to Kali Linux ?

    • @Destrudo5359
      @Destrudo5359 День назад

      @filippogiorgiorondo6932 Yah. It was under dashboard settings. There is an option to have the ElasticSearch side panels viewed as "classic style" Then I will show each section like security, Dashboard etc....also the defend was successfully installed on my end on kali machine command prompt once I was on a good internet connection. All good. Everything works as the video stated.

  • @alonarms123
    @alonarms123 5 дней назад +1

    Idk about anyone else but I can't find Logs under Observability. Any ideas?

  • @Fit_Luke
    @Fit_Luke 4 месяца назад +1

    Thanks for sharing this!

  • @ARE_Andon
    @ARE_Andon 9 дней назад

    what are the recommended computers for homelab that are cost friendly? Not sure if I need to get a new computer that is just reserved for homelabs. Can someone point me in the right direction recommended homelab computers and any accessories that should be included?

  • @efherrera01
    @efherrera01 2 месяца назад

    Hi, I am having trouble pasting the Linux command into the terminal in my virtual machine. It's not pasting. Any insight?

  • @franklinmccullough85
    @franklinmccullough85 11 месяцев назад +1

    I'm having trouble getting the rule for Nmap. I can get process.args:, but nap doesn't show up for me. Please advise.

  • @javierruiz2870
    @javierruiz2870 8 месяцев назад +1

    The process.args: nmap logs are not showing up on ES. I did everything just like the video up to that point. I've been stuck with this issue for several days now...

    • @SCole07
      @SCole07 7 месяцев назад

      Thank you​@@Kaiomonchi

    • @sloth1762
      @sloth1762 5 месяцев назад

      @@SCole07 what was the solution? I have the same issue

  • @Trotsky1981
    @Trotsky1981 Месяц назад

    This doesn't work anymore. Added the agent to kali, checked systemctl, did a few scans.. It sees the agent but there is nothing in the logs.

  • @abhiraampasaladi8121
    @abhiraampasaladi8121 27 дней назад +1

    This is not working. The setup of elasticsearch itself is a mess, unable to get it. Even after enrolling, only the logs during enrollment are only getting received in elastic and the rest after enrollment logs are not getting feeded.

  • @2kslimey
    @2kslimey 9 месяцев назад

    is elastic lab actually used in a professional setting or just for testing and building home labs?

  • @lieoling128
    @lieoling128 2 месяца назад

    Hi, I followed your steps to set up the nmap detection alert. But I cannot receive any emails for the alert. Do anyone know how to solve this problem?

  • @KennithJay
    @KennithJay Год назад +1

    Loved It. Excellent

  • @annmae644
    @annmae644 9 месяцев назад

    question on installing, when installing Kali, am i installing Vmware or virtualbox? i already have oracle vm virtualbox?

  • @BigHomieJay21
    @BigHomieJay21 8 месяцев назад +4

    Am I the only one not getting alerts? I set up the alerts and everything exactly as the video states and I have yet to get an alert or email from performing a Nmap scan

    • @lmartin2422
      @lmartin2422 6 месяцев назад

      me too. did anything change for you? if so, how did you do it?

    • @babatunde4874
      @babatunde4874 5 месяцев назад +3

      You need to use a different field-name
      (process.args : ‘’nmap’’) and not event.action.

    • @IvanAAnnuh
      @IvanAAnnuh 5 месяцев назад +2

      He used the wrong field name to create the rule, that is why. So use process.args: "nmap" rather than event.action: "nmap_scan" in the query when creating the rule.

    • @MperorPogPatine
      @MperorPogPatine 2 месяца назад

      @@IvanAAnnuh I still dont get any alerts, was there any other solution you found to trigger alerts?

  • @VincentKwaghtese
    @VincentKwaghtese 4 месяца назад

    It is very good to become one of a cyber professional

  • @nijatrzayev9962
    @nijatrzayev9962 Год назад +1

    You are doing great Gerald, Thanks for these invaluable resources.

  • @khadijahdolapoadesina1600
    @khadijahdolapoadesina1600 4 месяца назад

    good morning over here
    please am i the only one having issues with my elastic defend, its installing but not enrolled and i tried pinging google and it turned out fine

  • @ever6
    @ever6 5 месяцев назад

    wOW awesome channel I'm new here and just subscribed and recently finished my bootcamp and have to finish my resume before the jog hunt I'm in a 12 weeks mentor program now with cnl and this channel about projects will be great to add on my resume. I'm switching from 20yrs in motion apture animation in videogames/vfx film to a new career too many layoffs in games but plenty in cyber. I'll post update here when I finish this project hopefully before this weekend,.
    Darrel C

  • @boyejohnson4287
    @boyejohnson4287 2 месяца назад

    Great video, thank you.

  • @davidp5280
    @davidp5280 Год назад +2

    Good morning everyone! Nothing better than sharing and learning! Love it, love it, LOVE IT!!!❤🎉

  • @danielleglover8111
    @danielleglover8111 5 месяцев назад

    Im so new here. hpwever im struggling to find the downloads. i downloaded it but where do i find the boxes inside of oracle and linux that look like the ones above?

  • @brayan0742
    @brayan0742 3 месяца назад

    For some reason, I'm not getting any entries logs from nmap to the ES. Does anybody know how to fix this?

  • @Fran-yg4jp
    @Fran-yg4jp 3 месяца назад

    Gerald is there open source SIEM that I install on Ubuntu desktop that has a GUI ? I tried Wazuh , but having some issue with that and I have more resources on my Ubuntu also. Thanks in advance

  • @derocksta
    @derocksta 9 дней назад

    I can’t find the log menu

  • @CyberMonk-z3e
    @CyberMonk-z3e 4 месяца назад

    everything done but whatto do with this lab? i am confused, someone help me here

  • @trunksbrief4576
    @trunksbrief4576 27 дней назад

    Am I suppose to type the password when it says "[sudo] password for kali" after I pasted the code to install the agent in kali? if so its not letting me type anything when it gets to that point .

    • @trunksbrief4576
      @trunksbrief4576 27 дней назад

      I've figured it out now but now it wont successfully install the agent and I pinged googled like it said and it works
      It says agent is installed but currently broken

    • @trunksbrief4576
      @trunksbrief4576 12 дней назад

      Got it ✅ made a new elastic account free trial expired

  • @ellatechie
    @ellatechie 12 дней назад

    Not sure what I'm doing wrong but it doesn't confirm agent enrollment. I'm stuck at a "Listening for agent" message. Anyone else? Could use some help on how to fix this so I can finally complete the lab

  • @mihir1722
    @mihir1722 2 месяца назад

    does anyone know how he does the highlight thingy( the sqaure and the arrow) its my first time seeing someone use it, is a software or a inbuilt function, what is it

    • @mihir1722
      @mihir1722 2 месяца назад

      it just seems so helpful when writing documenting the stuff ur doing

    • @SimplyCyber
      @SimplyCyber  2 месяца назад

      It’s “zoomit” it’s part of a utility kit you can download from Microsoft

  • @babatunde4874
    @babatunde4874 5 месяцев назад

    For those having issues with not being able to get alerts/emails, it's because he used the wrong field-name for the rule.
    You need to use a different field-name
    (process.args : ‘’nmap’’) and not event.action.

  • @ishajatania6980
    @ishajatania6980 9 месяцев назад

    My fleet agent is not getting connected and the status is showing "listening" but not getting confirmed..What might be the problem please help me

  • @jworrell89
    @jworrell89 Год назад

    What do you use to highlight and make the arrow?.

    • @SimplyCyber
      @SimplyCyber  Год назад

      Zoom it by by systernals. It’s in Microsoft website. It’s awesome

  • @markkennedy5449
    @markkennedy5449 5 месяцев назад

    What’s the option for OS system???

  • @MichaelDaniele-n9c
    @MichaelDaniele-n9c 3 месяца назад

    I did everything as shown but when running "nmap" i do not get any alerts! please help

    • @abhinavakaranth3813
      @abhinavakaranth3813 3 месяца назад

      Go to "Stack Management"-> "Connectors". Test your connector
      OR
      While creating a new rule, in custom query, put process.args: "nmap" instead of event.action
      I was able to receive alerts when i changed the custom query from event.action to process.args

    • @brayan0742
      @brayan0742 3 месяца назад +1

      @@abhinavakaranth3813 I dont think that's he problem, I think the problem is that he's not getting any entries logs at all. I'm having the same issue.

  • @jonathanvasquez393
    @jonathanvasquez393 10 месяцев назад

    the only issue i had i could not find custom query in my options :/

  • @christopherayres164
    @christopherayres164 Год назад +2

    Well done, now how deep does this rabbit hole go? Just remember to keep following that white rabbit neo!

  • @letsgoheat23
    @letsgoheat23 Год назад +1

    Having trouble doing with a Mac. I know it has to do with the linux distribution.
    89

  • @SirDodge
    @SirDodge 11 месяцев назад +6

    Who's actually been able to get this SIEM to work? I haven't. After a successful agent install and nmap scans, nothing is being reported to the Logs about the scans.

    • @eshajadoun5743
      @eshajadoun5743 10 месяцев назад +1

      Even i am having trouble seeing the logs. But if you go to discover you will find timestamps of the data, and that means the thing is working

    • @SirDodge
      @SirDodge 10 месяцев назад

      @@eshajadoun5743 I'm glad to see that I'm not the only person who was having trouble and it wasn't just a newbie mistake but Yeah, I've just been messing around with it and setup a Kali VM and Windows VM as well as a honeypot and I've been seeing data being ingested over the last couple of days.

    • @giangphamngocchau8516
      @giangphamngocchau8516 7 месяцев назад

      same here. Have you been able to figure out the solution? Thanks in advance

    • @SirDodge
      @SirDodge 7 месяцев назад

      @@giangphamngocchau8516 Hi, I never finished "this" lab but I did pay for the course and the course is worth it.

    • @babatunde4874
      @babatunde4874 5 месяцев назад

      You need to use a different field-name
      (process.args : ‘’nmap’’) and not event.action.

  • @Ben-bf4gn
    @Ben-bf4gn Год назад

    I'm wondering if its possible to build this lab on prem (vs using the cloud)?

    • @SimplyCyber
      @SimplyCyber  Год назад

      It is, but you need more hardware and configuration. Check out graylog or ELK stacks.

  • @garymorris4505
    @garymorris4505 14 дней назад

    How am I just finding this Video, I’m building this ASAP

  • @Iamjustja
    @Iamjustja Год назад +1

    Great content.

  • @LearningDFIR
    @LearningDFIR 6 месяцев назад

    Great video! Late comment but, how long does the free version can be used?

    • @SimplyCyber
      @SimplyCyber  6 месяцев назад

      It’s been a minute but I think 7 or 14 days. I can’t recall but enough you can make it happen in a weekend

  • @Yoga-Psicanálise
    @Yoga-Psicanálise 6 месяцев назад

    everything went well but I didn't get any alert even in the dashboard and in my e-mail

    • @SimplyCyber
      @SimplyCyber  6 месяцев назад

      🤔 hmmm

    • @shockwave716
      @shockwave716 5 месяцев назад +2

      I'm running into the same thing. Wondering if our KQL syntax for the rule is outdated or incorrect.

  • @abdielramos8403
    @abdielramos8403 Год назад

    This is good for people that are starting with Cybersecurity or prior "experience"/background is necessary?

    • @SimplyCyber
      @SimplyCyber  Год назад +3

      No experience is needed to setup, but prior knowledge is needed to know what you’re looking at and what it means in the siem. Mostly networking and operating system prior knowledge

    • @abdielramos8403
      @abdielramos8403 7 месяцев назад

      I'm back and ready to spend time to learn and earn experience. Currently starting my major in cybersecurity and want to earn experience at the same time to build my resume.

  • @techroamin
    @techroamin Год назад

    Hell yes gerry guy, i’m doing this soon

    • @RowanHawkins
      @RowanHawkins 11 месяцев назад

      Don't do anything soon. if you want to do something put a date on it. Soon to some software devs is 2.5 years of soon.

  • @Fry28tv
    @Fry28tv 6 месяцев назад +2

    event.action: "nmap_scan" doesn't work, wouldn't trigger any alerts.

    • @IvanAAnnuh
      @IvanAAnnuh 5 месяцев назад +1

      He used the wrong field name to create the rule, that is why. So use process.args: "nmap" rather than event.action: "nmap_scan" in the query when creating the rule.

  • @kayodeolanrewaju5459
    @kayodeolanrewaju5459 6 месяцев назад

    it gave me an error
    curl: (18) HTTP/2 stream 1 was not closed cleanly before end of the underlying stream
    tar (child): elastic-agent-8.14.2-linux-x86_64.tar.gz: Cannot open: No such file or directory
    tar (child): Error is not recoverable: exiting now
    tar: Child returned status 2
    tar: Error is not recoverable: exiting now
    bash: cd: elastic-agent-8.14.2-linux-x86_64: No such file or directory
    what do i do??

    • @SimplyCyber
      @SimplyCyber  6 месяцев назад

      Ping me on the discord server. I’m not sure what step you’re on or what you’re doing that results in this error and yt comments is tough to communicate for troubleshooting

    • @kayodeolanrewaju5459
      @kayodeolanrewaju5459 6 месяцев назад

      @@SimplyCyber alright, I'm trying something now but I'll ping you if this doesn't work out as well

  • @jamilpotts8558
    @jamilpotts8558 5 месяцев назад

    Anyone know of a completely free SIEM we could use in lieu of a trial version of Elastic? Just wondering.

  • @freshkicks23023
    @freshkicks23023 6 месяцев назад

    why does elastic look completely different and not work the same. plz help

    • @SimplyCyber
      @SimplyCyber  6 месяцев назад

      Im not sure. technology can have front end changes made after the video is recorded. potentially that?

  • @jacovanderwalt13
    @jacovanderwalt13 5 месяцев назад

    is there something to use instead of elastic, that is 100% free and not trial? thnx

    • @SimplyCyber
      @SimplyCyber  5 месяцев назад

      its been a minute but i think there is a trial aspect to this so its just an in/out opportunity to learn and do a lab.

    • @SimplyCyber
      @SimplyCyber  5 месяцев назад +1

      I believe Graylog is free

    • @jacovanderwalt13
      @jacovanderwalt13 5 месяцев назад

      @@SimplyCyber great thank you i will check it out. still new in CS scene but allready completed S+ and big interest in expanding my knowledge in SC.

    • @gavbam
      @gavbam 2 месяца назад

      Try Wazuh its a fork of elastic and will be widely used in training labs

  • @CyberDreams11
    @CyberDreams11 9 месяцев назад

    I couldn't get past the Elastic install point

  • @TheSilentLearner786
    @TheSilentLearner786 Год назад

    Sir expecting more siem lab tutorials❤

  • @milanmills2824
    @milanmills2824 6 месяцев назад

    Maybe it worked before but doesn’t work anymore. Doesn’t installs

  • @sumitm_11
    @sumitm_11 5 месяцев назад

    Thank you

  • @treyanmarioh
    @treyanmarioh 10 месяцев назад +2

    I am happy you exist.

  • @tommyshowgun
    @tommyshowgun Год назад

    Thank you.

  • @razulconde8765
    @razulconde8765 Год назад +2

    Remarkable Man, Thanks, but slow down a bit. Are you in a rush or something else?

  • @Dkidd076
    @Dkidd076 Год назад +1

    #TeamSimplyCyber!

  • @elatedvids7354
    @elatedvids7354 3 месяца назад

    Can someone confirm, does this work now?

  • @Lilkevtalk
    @Lilkevtalk 3 месяца назад +1

    Did hours of tinkering just to realize my nmap commands and stuff don’t work or transfer anything to my elastic defender logs.

    • @BrianBChess
      @BrianBChess 3 месяца назад

      did you find a way to fix that?

    • @Lilkevtalk
      @Lilkevtalk 20 дней назад

      @@BrianBChess about to try again soon

  • @tyrojames9937
    @tyrojames9937 Год назад

    COOL!

  • @DivineDreamDivine
    @DivineDreamDivine Год назад +1

    #TeamSC

  • @Destrudo5359
    @Destrudo5359 Месяц назад +1

    Looks completely different from dashboard on elastic. Could probably use an updated video.

    • @SimplyCyber
      @SimplyCyber  Месяц назад +1

      Thx for update. I’ll add it the queue. Will probably pull this one down

    • @Destrudo5359
      @Destrudo5359 Месяц назад

      @@SimplyCyber thank you.

  • @everythingisalie3363
    @everythingisalie3363 22 дня назад

    Subbed based off comments