From e244cf8a330e28f6154ad9c1fd074ffe114bdf6a Mon Sep 17 00:00:00 2001 From: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> Date: Wed, 27 Nov 2019 14:11:05 -0500 Subject: [PATCH] Added endgame-* index and new heading 3 Elastic Endpoint SMP. (#51071) (#51828) --- docs/siem/index.asciidoc | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/docs/siem/index.asciidoc b/docs/siem/index.asciidoc index c947e000c8138..f56baf6abdc2e 100644 --- a/docs/siem/index.asciidoc +++ b/docs/siem/index.asciidoc @@ -24,7 +24,7 @@ Kibana provides step-by-step instructions to help you add data. The detailed information and instructions. [float] -=== {Beats} +=== {Beats} https://www.elastic.co/products/beats/auditbeat[{auditbeat}], https://www.elastic.co/products/beats/filebeat[{filebeat}], @@ -33,9 +33,14 @@ https://www.elastic.co/products/beats/packetbeat[{packetbeat}] send security events and other data to Elasticsearch. The default index patterns for SIEM events are `auditbeat-*`, `winlogbeat-*`, -`filebeat-*`, and `packetbeat-*``. You can change the default index patterns in +`filebeat-*`, `endgame-*`, and `packetbeat-*``. You can change the default index patterns in *Kibana > Management > Advanced Settings > siem:defaultIndex*. +[float] +=== Elastic Endpoint Sensor Management Platform + +The Elastic Endpoint Sensor Management Platform (SMP) ships host and network events directly to the SIEM application, and is fully ECS compliant. + [float] === Elastic Common Schema (ECS) for normalizing data