Closed t3chn0m4g3 closed 6 years ago
I guess ELK Stack v5 is still in the making. I just wanted to highlight this nice new future:
X-PACK (https://www.elastic.co/products/x-pack/machine-learning) offers now time series anomaly Detection. This tool will automatically alert on unusual changes in a key performance indicator values.
This might come in very handy for automatic detection of new attacks on the honeypot sensors, not only the usual radiation.
Indeed, ELK 5.x will be baked into 17.06 without X-Pack. Due the licensing scheme it is not suited for an open source project like T-Pot.
It would be nice if a key was supplied, that it would auto install it.
As mentioned earlier, X-Pack will not be part of T-Pot.
Any update when tpot 17.06 will be released.
@melazzouzi I was planning with a first alpha at the end of June. Some delays in the logstash geo_ip filter (ASN functionality) as well as some new features (vs. time available) might point to a GA release in September or even October, probably as a T-Pot 17.10 😇
we will loose maxmind ASN feature due to limitation of logstash geo plugin (will only read .mmdb, no more .dat)