brentcox820 / sa_ramp_2.0

Session Activities and Homework for the SA Ramp 2.0 Enablement by Brent Cox
3 stars 0 forks source link

Session 1 | 7.24.2023 #1

Open brentcox820 opened 1 year ago

brentcox820 commented 1 year ago

Meeting 1:

::Activies and Agenda::

:: Start Collection Data via AGENT::

sudo ./elastic-agent install --url=https://f2f020c66d8a4fd4aa043885f69316e3.fleet.us-west-2.aws.found.io:443 --enrollment-token=NWJwZmtJa0JqdmZ0RmtjT0lSQno6cEQtUlVpWXNURWlWS0tPT0RKUVZvQQ==
sudo elastic-agent enroll --url=https://f2f020c66d8a4fd4aa043885f69316e3.fleet.us-west-2.aws.found.io:443 --enrollment-token=NWJwZmtJa0JqdmZ0RmtjT0lSQno6cEQtUlVpWXNURWlWS0tPT0RKUVZvQQ==
cd /Library/Elastic

:: Elastic Agent via POC / POV::

:: Elastic Agent via REAL WORLD::

::HOMEWORK:::

  1. Ensure your Elastic Agent is connected and sends metrics and logs to your Elastic deployment.
    • Please ensure that Elastic Defend is on the integrations list for the new Policy your agent is connected to and linked to your deployment.
  2. If you are having issues with this, uninstall and reinstall the agent and re-enroll the agent, and that will solve the 404 Fleet auth issue with the old token.
jendavido commented 1 year ago

LFG!