Hi All,
Any advice on how to go about finding coverage gaps in a typical ES installation ?We r ingesting logs from AWS, and On prem servers both. Is there any document or tool that i can use to find out whats missing , whats covered and overall gap analysis ?
Also, Can someone pls point me to typical/ important Dashboards that we can leverage for every day security tasks, other than default out of the box ones ?