CONTACT US
forrester wave report 2023

Close your ransomware case with Open NDR

SEE HOW

Download our free guide to find hidden attackers.

Find hidden attackers with Open NDR

SEE HOW

cloud-network

Corelight announces cloud enrichment for AWS, GCP, and Azure

READ MORE

partner-icon-green

Corelight's partner program

BECOME A PARTNER

glossary-icon

10 Considerations for Implementing an XDR Strategy

READ NOW

ad-images-nav_0006_Blog

Don't trust. Verify with evidence

READ BLOG

video

The Power of Open-Source Tools for Network Detection and Response

WATCH THE WEBCAST

ad-nav-ESG

The Evolving Role of NDR

DOWNLOAD THE REPORT

ad-images-nav_0006_Blog

Detecting 5 Current APTs without heavy lifting

READ BLOG

g2-medal-best-support-spring-2024

Network Detection and Response

SUPPORT OVERVIEW

 

Corelight Announces Full Support for Elastic Common Schema for Simplified Search and Analytics Capabilities

SAN FRANCISCO, Jan. 28, 2020 /PRNewswire/ -- Corelight, provider of the most powerful network traffic analysis (NTA) solutions for cybersecurity, today reinforced its support for the Elastic Common Schema (ECS) , a specification that provides a consistent and customizable way to structure log data from a variety of diverse sources in Elasticsearch. Using Corelight ECS Mapping streamlines the implementation of automated analysis methods on Zeek logs, including machine learning-based anomaly detection and alerting. 

Corelight, the leading provider of the most powerful network traffic analysis (NTA) solutions for cybersecurity (PRNewsfoto/Corelight)

"Corelight was one of the first Elastic partners to test ECS when it was launched in 2019 . Our support for ECS underscores a mutual focus on providing customers with a standardized approach on how to collect, ingest and understand their data," said Allen Male, director of strategic alliances and partnerships for Corelight. "These efforts help customers make use of enhanced capabilities that reduce their security risk without additional analyst effort."

ECS facilitates the unified analysis of data from diverse sources so that content such as dashboards and machine learning jobs can be applied more broadly, searches can be crafted and shared more efficiently, and field names can be recalled by analysts more easily.

"The Elastic Common Schema provides a shared language for our community of users to understand their data, collaborate to develop resources across the Elastic Stack, and more quickly drill down to identify a potential attacker or determine the root cause of an operational issue," said Mike Paquette, director of product, Elastic SIEM. "Mapping to ECS makes it easier for users to visualize, search, drill down, and pivot through their Zeek log data, and enables easy sharing of analysis content amongst the Zeek user community."

ECS streamlines the development of analytics content. Instead of creating new searches and dashboards each time an organization adds a data source with a new format, users can continue leveraging ECS-aware searches and dashboards. ECS also makes it far easier for organizations to directly adopt analytics content from other parties that use ECS, whether Elastic, a partner, or an open source project.

Corelight ECS mapping supports Corelight data as well as open-source Zeek and is available on Github .

For more information on ECS check out the " Introducing Elastic Common Schema " post on the Elastic blog.

Corelight product marketing has also described the benefits of Corelight ECS Mapping in its " Corelight ECS Mapping: Unified Zeek data for more efficient analytics " post now available on the Corelight blog.

About Corelight
Corelight makes powerful network traffic analysis (NTA) solutions that transform network traffic into rich logs, extracted files, and security insights for more effective incident response, threat hunting, and forensics. Corelight Sensors run on Zeek (formerly called "Bro"), the open-source network security monitoring tool used by thousands of organizations. Corelight Sensors simplify Zeek deployment and expand its performance and capabilities. Corelight's global customers include Fortune 500 companies, major government agencies, and large research universities. Corelight is based in San Francisco, Calif. For more information, visit https://www.corelight.com or follow @corelight_inc.

 

Cision View original content to download multimedia:http://www.prnewswire.com/news-releases/corelight-announces-full-support-for-elastic-common-schema-for-simplified-search-and-analytics-capabilities-300994169.html

SOURCE Corelight, Inc.