mirror of
https://github.com/elastic/kibana.git
synced 2025-04-24 17:59:23 -04:00
[DOCS] Adds info for ML auditbeat module (#28969)
This commit is contained in:
parent
14bbd20d85
commit
752f98769d
4 changed files with 12 additions and 3 deletions
|
@ -20,19 +20,28 @@ than running multiple jobs against the same data.
|
||||||
|
|
||||||
A _population job_ detects activity that is unusual compared to the behavior of
|
A _population job_ detects activity that is unusual compared to the behavior of
|
||||||
the population. For more information, see
|
the population. For more information, see
|
||||||
{stack-ov}/ml-configuring-pop.html[Performing Population Analysis].
|
{stack-ov}/ml-configuring-pop.html[Performing population analysis].
|
||||||
|
|
||||||
An _advanced job_ can contain multiple detectors and enables you to configure all
|
An _advanced job_ can contain multiple detectors and enables you to configure all
|
||||||
job settings.
|
job settings.
|
||||||
|
|
||||||
{kib} can also recognize certain types of data and provide specialized wizards
|
{kib} can also recognize certain types of data and provide specialized wizards
|
||||||
for that context. For example, if you use {filebeat-ref}/index.html[Filebeat]
|
for that context. For example, if you use {filebeat-ref}/index.html[{filebeat}]
|
||||||
to ship access logs from your
|
to ship access logs from your
|
||||||
http://nginx.org/[Nginx] and https://httpd.apache.org/[Apache] HTTP servers to
|
http://nginx.org/[Nginx] and https://httpd.apache.org/[Apache] HTTP servers to
|
||||||
{es}, the following wizards appear:
|
{es}, the following wizards appear:
|
||||||
|
|
||||||
[role="screenshot"]
|
[role="screenshot"]
|
||||||
image::ml/images/ml-data-recognizer.jpg[A screenshot of the Apache and NGINX job creation wizards]
|
image::ml/images/ml-data-recognizer-filebeat.jpg[A screenshot of the {filebeat} job creation wizards]
|
||||||
|
|
||||||
|
Likewise, if you use {auditbeat-ref}/index.html[{auditbeat}] to audit process
|
||||||
|
activity on your systems, the following wizards appear:
|
||||||
|
|
||||||
|
[role="screenshot"]
|
||||||
|
image::ml/images/ml-data-recognizer-auditbeat.jpg[A screenshot of the {auditbeat} job creation wizards]
|
||||||
|
|
||||||
|
These wizards create {ml} jobs, dashboards, searches, and visualizations that
|
||||||
|
are customized to help you analyze your {auditbeat} and {filebeat} data.
|
||||||
|
|
||||||
If you are not certain which type of job to create, you can use the
|
If you are not certain which type of job to create, you can use the
|
||||||
*Data Visualizer* to learn more about your data and to identify possible fields
|
*Data Visualizer* to learn more about your data and to identify possible fields
|
||||||
|
|
BIN
docs/ml/images/ml-data-recognizer-auditbeat.jpg
Normal file
BIN
docs/ml/images/ml-data-recognizer-auditbeat.jpg
Normal file
Binary file not shown.
After Width: | Height: | Size: 173 KiB |
BIN
docs/ml/images/ml-data-recognizer-filebeat.jpg
Normal file
BIN
docs/ml/images/ml-data-recognizer-filebeat.jpg
Normal file
Binary file not shown.
After Width: | Height: | Size: 169 KiB |
Binary file not shown.
Before Width: | Height: | Size: 250 KiB |
Loading…
Add table
Add a link
Reference in a new issue