D3 integrates with Elasticsearch, the search and analytics engine at the heart of the Elastic stack. Elasticsearch aggregates and stores data and logs for careful monitoring and detailed analysis. Predefined queries in Elasticsearch can generate alerts that are escalated to D3 for investigation of possible security concerns. D3 can also enrich events from other sources by querying Elasticsearch for additional context.
Download This Solution Guide:
- How D3 turns Elasticsearch data into automation-powered investigations
- How D3 queries Elasticsearch to find related events and fill in the kill chain of an attack
- How D3’s integrations with 360+ tools supports orchestration of response to Elasticsearch alerts