I have a general question for those that are admins or users of Enterprise Security. I am tasked with considering what searches or panels that I will be placing in a dashboard that may be useful to the users of Enterprise Security regarding system health. While this generally is more of an administrative concern, I still have to present something that may be of interest to those who are actively using ES from a SOC perspective and relevant health or threshold searches (alerts) that may be of interest to them. While I have some basic thoughts from ES Health dashboards, what would some of you consider using or presenting to your end users of Enterprise Security?
This is a general discussion so any input is appreciated. Feel free to comment and I will reply as needed over the next few days. Thank you!
There are a number of dashboards and panels in the audit domain of ES that can provide valuable insights to various parts of your SOC. Some are more engineering/ops centric like search audit (what kinds of searches are being executed against the system, both ad-hoc and scheduled), as well as the indexing and forwarding dashboards and others. The IR and Suppression dashboards are useful to the analysts leadership to see who is processing what and when and which correlation searches are taking longer to service than others. All of these can be cloned and modified as you see fit as well.
One useful dashboard that you may want to consider adding is one that looks at different data sets and shows when you last received data from the source or if you want to narrow the aperture, specific hosts/systems and when you last received logs from the system. If a device is not very chatty due to where it sits on the network or has a narrow rule set on it, you may want to have some idea if the lack of data coming from that system is what you would expect or if something has gone sideways that is preventing data from coming from that system.
Hope this helps.