官方文件
Alert type
Any type - Match on any event matching a given filter
Frequency type - Match where there are X events in Y time
Spike type - Match when the rate of events increases or decreases
Flatline type - Match when there are less than X events in Y time
Blacklist type - Match when a certain field matches a blacklist
Whitelist type - Match when a certain field matches a whitelist
Elasticsearch 結合realm + LDAP
出處:User Impersonation with X-Pack: Integrating Third Party Auth with Kibana
簡介
X-Pack Security 提供 authentication and authorization via RBAC
authentication:認證,透過Elasticsearch原生的realm來做管理
authorization:有哪些權限