Enhancing Security Through Data Analysis and Visualization with ELK
摘要
In a world where data is an organization’s most valuable asset, the challenge lies not only in securing it but also in extracting actionable insights. This paper explores the symbiotic relationship between data analysis, visualization, and security, with a particular focus on the ELK Stack (Elasticsearch, Logstash, Kibana). By harnessing the power of ELK, businesses can elevate their security posture by effectively analyzing and visualizing data, enabling swift threat detection and informed decision-making. Our use case consists in studying and setting up a solution for managing logs and security events. This solution, which will allow the collection and the transformation of the logs of various bricks of the IS, aims in particular to obtain information allowing the detection of abnormal behavior in order to remedy it with the necessary measures, and the reduction of the response time to incidents that may partially or completely paralyze information system activities.