Summary

  • The writer is discussing setting up a system to gather data from Windows and Linux machines using Elastic’s software.
  • Elastic provides Beats, which are lighter shippers that send different types of operational data to Elasticsearch, and Elastic Agent, which unifies the collection of logs, metrics, security data, and threat prevention.
  • Elastic Agent can be managed centrally through Kibana’s Fleet app, or manually by advanced users, the latter using a YAML file.
  • Fleet Server is a component that connects Agents to Fleet, and supports many Agent connections.
  • Fleet Server is used to update agent policies, collect status information, and coordinate actions across Elastic Agents.
  • As the number of Agents grows, multiple Fleet Servers can be deployed for scalability.

By Ghostploit

Original Article