To ingest data, you can use:
- The Elastic Agent with the Elastic Endpoint Integration, which protects your hosts and sends logs, metrics, and endpoint security data to Elastic Security (see Configure and install Elastic Endpoint Integration (beta)).
- Beats shippers installed for each system you want to monitor.
- Third-party collectors configured to ship ECS-compliant data. Elastic Security ECS field reference provides a list of ECS fields used in Elastic Security.
If you use a third-party collector to ship data to Elastic Security, you must
map its fields to the Elastic Common Schema (ECS). Additionally,
you must add its index to the Elastic Security indices (Kibana →
Stack Management → Advanced Settings →
Elastic Security uses the
host.name ECS field as the
primary key for identifying hosts.
The Elastic Agent with the Endpoint Security Integration ships these data sources:
- Process - Linux, macOS, Windows
- Network - Linux, macOS, Windows
- File - Linux, macOS, Windows
- DNS - Window
- Registry - Windows
- DLL and Driver Load - Windows
- Security - Windows
Install Beats shippersedit
To populate Elastic Security with hosts and network security events, you need to install and configure Beats on the hosts from which you want to ingest security events:
You can install Beats using the Kibana UI guide or directly from the command line.
Install Beats using the Kibana UI guideedit
Click Home → Add events, and follow the links for the types of data you want to collect.
Download and install Beats from the command lineedit
To install Beats, see these installation guides:
Enable modules and configuration optionsedit
No matter how you installed Beats, you need to enable modules in Auditbeat and Filebeat to populate Elastic Security with data.
For a full list of security-related beat modules, click here.
To populate Hosts data, enable these modules:
- users and groups
- Auditbeat auditd module - Linux kernel audit events
- Auditbeat file integrity module - Linux, macOS, Windows
- Filebeat system module - Linux system logs
- Filebeat Santa module - macOS security events
- Winlogbeat - Windows event logs
To populate Network data, enable Packetbeat protocols and Filebeat modules: