Balancers Nodes (2) Logstash Elasticsearch Kibana X-pack Authentication X-pack AD Instances (2) Master/Data Nodes (4) Version 5.0 across the board 2TB Pure storage per elasticsearch node The worst grok filter ever
Firewall Load Balancers Elasticsearch X-pack Master/Data Nodes (8) Kibana X-pack Instances (2) Nodes (2) Logstash Authentication AD MOAR NODES Bumped each ES node up to 4TB, then 6TB Balanced index sizes
X-pack AD Instances (2) Master Nodes (3) Coordinating Nodes (3) Data Nodes (10) Beats Log Files Metrics Windows Events Firewall Load Balancers Nodes (2) Logstash Heartbeats X-pack Cloud Monitoring Chad came to visit Dedicated roles Still more nodes
AD Instances (2) Master Nodes (3) Coordinating Nodes (3) Data Nodes (10) Beats Log Files Metrics Windows Events Firewall Load Balancers Nodes (2) Logstash Heartbeats X-pack Cloud Monitoring Nodes (3) Production Non-production Master Nodes (3) Data Nodes (8) Production Non-production Instances (1) Production Non-production A place to test TLS all the things Cross-cluster search
provided our team's efforts. It's allowed us to stretch our reach into new data investigation territory and snap back on adversaries in a shorter period of time. - Abe Miller, InfoSec
powerful tools and insights to combat previously undetected enemies hidden within our codebase. In short: we can slay dragons now. - Joe Stetzer, Dev Lead