Articles By Dale McDiarmid

August 3, 2017 Engineering

Integrating Elasticsearch with ArcSight SIEM - Part 6 - Detecting Unusual Processes with X-Pack Machine Learning

By Dale McDiarmidMike Paquette

In this post we explore a more automated approach to the same challenge using machine learning.

June 14, 2017 Engineering

Integrating Elasticsearch with ArcSight SIEM - Part 5

By Dale McDiarmid

Last time we identified a brute force login attack. Now we'll detect unusual processes on machines in your infrastructure using Elasticsearch and ArcSight.

May 30, 2017 Engineering

Detecting Signs of Ransomware: WannaCry and the Elastic Stack

By Dale McDiarmid

This blog explores how the Elastic Stack can be used to triage malware outbreak and identify potential infections within your organisation.

May 3, 2017 Engineering

Operational Analytics with Elasticsearch at Elastic{ON} 2017 - Part 2

By Dale McDiarmidJesse Lovelace

A 3-part series on Operational Analytics demo at Elastic{ON}. This one looks are creating and using custom maps in Kibana.

April 11, 2017 Engineering

Operational Analytics with Elasticsearch at Elastic{ON} 2017 - Part 1

By Dale McDiarmidAsawari Samant

A 3 part series on Operational Analytics: Exploring attendee engagement at Elastic{ON} using the Elastic Stack.

April 4, 2017 Engineering

Integrating Elasticsearch with ArcSight SIEM - Part 4

By Dale McDiarmidMike Paquette

Utilising the Elastic Stack with ArcSight SIEM to alert on security events.

January 9, 2017 Engineering

Integrating Elasticsearch with ArcSight SIEM - Part 2

By Dale McDiarmidMike Paquette

Utilising the Elastic Stack with ArcSight SIEM to alert on security events

January 20, 2016 Releases

Deploying Elasticsearch with Ansible

By Dale McDiarmid

With the recent release of Elasticsearch 2.0.0 a completely new Ansible role has been released as well.

September 8, 2015 Engineering

When and How To Percolate - Part 2

By Dale McDiarmid

Following on from last week's post, we discuss optimising and scaling your Percolator instances to handle your document throughput.