Browse a library of EQL analytics now natively integrated in Elasticsearch since Endgame joined forces with Elastic. EQL in Elasticsearch accommodates non-security users with changes summarized in the Elasticsearch EQL documentation. Get started by installing the EQL module with Python 2.7 and 3.5+, then try a sample json file and test it with EQL commands.
FEATURES
SIMILAR TOOLS
Elastic is a search-powered AI company that enables users to find answers from all data in real-time at scale.
Serverless, real-time data analysis framework for incident detection and response.
A dynamic GUI for advanced log analysis, allowing users to execute SQL queries on structured log data.
Investigate malicious logons by visualizing and analyzing Windows Active Directory event logs with LogonTracer.
Sysmon for Linux is a tool that monitors and logs system activity with advanced filtering to identify malicious activity.
A logging proxy tool created in response to the 'MongoDB Apocalypse', with Docker support.
Procmon for Linux is a reimagining of the classic Procmon tool from Windows, allowing Linux developers to trace syscall activity efficiently.