Open jt0dd opened 1 year ago
Just following up! Curious if the team decided to adopt this as a viable and planned feature. (@jsanz maybe you would have that answer?)
This has not been triaged yet by the team @jt0dd. This and the last week were busy here, let's give them some more time.
This is still very much needed. +1
Pinging @elastic/kibana-visualizations (Team:Visualizations)
Maybe this should be an Elastic Security / SIEM feature only, but a lot of people use Kibana as a SIEM already. I'm happy to migrate this elsewhere, just let me know the right repo.
With netflow and network traffic logs, it's possible to put together a pretty good picture of the network without manually building a map. I could write code easily to, for a given Elastic Index with Zeek logs, define a set of nodes and edges that accurately portray the structure of that network, in terms of the ares of it we can see in our dataset.
I want to be able to generate, within Kibana and / or Elastic Security, non-geographic, good looking network maps like these:
Currently there doesn't seem to be any way to do this in any Elastic product no matter how much coding I'm willing to put into it. The capability would be far better than needing to export the data into some third party tool.
Look at how beautifully (and practically) it's done here: https://www.datadoghq.com/blog/network-performance-monitoring/#observing-long-lived-abstractions
I see no reason Kibana couldn't add another type of chart / map to its built-in visualizations for this. The same way the current visualization / chart builder feature lets me tell Kibana which properties I want to correspond to each aspect of the graph, the same thing could be done with me using the GUI to tell Kibana which data properties correlates to nodes and edges in this network map.
Please include:
I originally wrote this out as a more elaborate Kibana API based feature, as follows (which I'm leaving in just to clarify the approach I'm thinking of):