Home / Companies / Elastic / Blog / May 2022

May 2022 Summaries

40 posts from Elastic

Filter
Month: Year:
Post Summaries Back to Blog
Terraform, a popular infrastructure-as-code tool, can be used to manage Elastic Cloud resources by utilizing two specific providers: the Elastic Cloud provider and the Elasticstack provider. This integration allows users to automate the deployment, configuration, and management of Elasticsearch and Kibana instances without relying on the Elastic Cloud UI. Users can define infrastructure configurations in Terraform files and execute commands to initialize, validate, and apply these configurations, enabling seamless cluster management, including setting up Cross Cluster Search (CCS) and Cross Cluster Replication (CCR). The Elasticstack provider further enhances functionality by allowing users to manage Elasticsearch components such as index pipelines and dashboards through Terraform scripts. This approach supports efficient and automated cloud operations, and users are encouraged to provide feedback and report issues on the respective GitHub repositories for these Terraform providers.
May 31, 2022 1,332 words in the original blog post.
As digital transformation accelerates, the impact on enterprises is just beginning, with 93% having invested in such projects, leading to 65% of global GDP being digitized by the end of 2022. Organizations leveraging cloud platforms like AWS, Google Cloud, and Microsoft Azure are transforming customer experiences and business decisions by turning static data into actionable insights. Experts suggest shifting focus from long-term projects to immediate business results, emphasizing data as a central asset while addressing internal silos and cultural issues. By empowering employees with greater access to data, companies can gain a competitive advantage in talent retention and productivity. This approach requires new policies and tools to facilitate data sharing and ensure that insights are actively utilized to drive business outcomes.
May 31, 2022 994 words in the original blog post.
Nearly half of organizations are considering replacing or augmenting their current Security Information and Event Management (SIEM) solutions due to several evolving needs, including the increased use of cloud technology, the demand for integrated data, and the necessity for faster response times. Research led by ThoughtLab, co-sponsored by Elastic, highlights that many executives, particularly CEOs and CTOs, are seeking SIEMs that can provide better visibility in cloud-native environments, advanced analytics, machine learning, and more integrated data capabilities. Elastic's cloud-based SIEM solution addresses these needs by offering features like the Elastic Common Schema for improved data integration and faster query responses, which are crucial for reducing the mean time to detect (MTTD) and mean time to respond (MTTR) to security threats. The Forrester Total Economic Impact™ study suggests that Elastic Security can significantly reduce data breach risks and costs, with businesses reporting faster query times and more efficient threat detection and response, ultimately leading to a reduction in business disruption costs by over $6.5 million over three years.
May 31, 2022 836 words in the original blog post.
Telecom providers are increasingly adopting cloud technologies, particularly Elastic Cloud, as they venture into 5G services to maintain competitiveness and explore new revenue streams. Elastic Cloud offers telecom companies the ability to scale services with agility and flexibility, which is crucial for meeting the demands of enterprise clients who require guaranteed quality-of-service and low-latency connections. Opportunities for growth in industries like retail and mobile gaming are highlighted, where improved connectivity and cloud capabilities can enhance customer experiences and operational efficiencies. Elastic Cloud's advanced machine learning support, autoscaling features, and cross-cluster search capabilities offer telecom businesses the means to optimize spending, improve network resource management, and facilitate innovative service delivery. The cloud's role in driving profitability and reducing operational costs is evidenced by a case study where a South American telecom provider achieved a 283% ROI and an 80% reduction in mean time to restore services after deploying Elastic Cloud. Elastic Cloud is positioned as a key partner for telecom providers, offering support throughout their cloud transition while ensuring operational flexibility and avoiding vendor lock-in.
May 26, 2022 1,011 words in the original blog post.
Version 8.2.2 of the Elastic Stack has been released, featuring various fixes and minor enhancements across its products, including Elasticsearch, Kibana, Beats, Logstash, Elastic Enterprise Search, Elastic Observability, APM, and Elastic Security. Users are advised to upgrade to this latest version to benefit from these improvements. Detailed information on the specific changes for each product can be found in the 8.2.2 release notes.
May 26, 2022 133 words in the original blog post.
The article explores the significance and evolution of personalization in modern business strategies, using Netflix as a prime example of success driven by personalized content recommendations. It highlights how personalization has evolved from simple algorithms to complex data-driven strategies, with the cloud playing a crucial role in enabling these advancements. As personalization expands beyond digital screens to include physical retail interactions, companies face challenges in data management, privacy, and avoiding over-personalization, which can alienate customers. The article suggests that cloud technology provides an efficient solution for integrating various IT systems, allowing businesses to harness real-time data analytics, improve customer experiences, and maintain a competitive edge. It emphasizes the need for empathy in personalization strategies to avoid crossing privacy boundaries and the importance of refining algorithms to better serve diverse customer needs.
May 25, 2022 1,464 words in the original blog post.
Many companies are accelerating their migration of critical databases to the cloud as the advantages increasingly outweigh the associated risks. A recent IDC study shows that 63% of companies are currently migrating databases to the cloud, with another 29% considering it within the next three years. This shift is driven by the need for increased access to innovation, improved security, and scalability to accommodate remote work environments. Legacy databases, while stable, are often too slow for modern digital business needs and are vulnerable to security threats. Cloud providers offer advanced AI services and automated security processes that most companies cannot implement internally. Moreover, the flexibility of cloud infrastructure allows businesses to scale efficiently without significant investments in their own data centers. The growing maturity of cloud migration options and the ability to utilize multiple cloud platforms further reduce the risk of vendor lock-in, making the transition more appealing. As a result, a recent survey from EDB indicates that 92% of companies are satisfied with their cloud migration efforts.
May 24, 2022 712 words in the original blog post.
Using Helm to implement Elastic Stack on ECK (Elastic on Kubernetes) offers a streamlined approach to establishing Kubernetes observability with just four commands, enabling the deployment of Elasticsearch, Kibana, Fleet, and Elastic Agents with system and Kubernetes metrics. This guide emphasizes the importance of adjusting chart values, specifically in the stack/charts/elasticsearch/values.yml file, to fit specific use cases, such as creating dedicated nodes for various roles like master, data, and ingest nodes. The process involves adding the Elastic Helm repository, installing the ECK operator, and then deploying either the entire stack or individual components like Elasticsearch or Kibana. Additionally, the setup facilitates the collection of logs and metrics from the Kubernetes cluster using Fleet and Elastic agents, with Fleet-server chart incorporating elastic-agent as a dependency, thus providing a robust solution for Kubernetes observability.
May 24, 2022 448 words in the original blog post.
Version 8.2.1 of the Elastic Stack was released on May 24, 2022, bringing important security fixes and minor enhancements to the suite of tools, which includes Elasticsearch, Kibana, Beats, Logstash, Elastic Enterprise Search, and Elastic Observability. The update addresses two security vulnerabilities, with specific improvements noted for the APM component, such as resolving a bug where events within batches improperly shared metadata labels. Users are recommended to upgrade to this latest version to benefit from these security updates and improvements, and further details are available in the release notes.
May 24, 2022 173 words in the original blog post.
Version 7.17.4 of the Elastic Stack was released on May 24, 2022, and it is recommended to upgrade to this latest version over previous patch versions in the 7.17.x series. This release addresses a potential security vulnerability, with further details available in the security advisory. The update includes fixes for issues across various Elastic Stack products, such as Elasticsearch, Kibana, Beats, Logstash, Elastic Enterprise Search, Elastic Observability, and Elastic Security. Notably, it resolves a bug in the Elastic Security Solution related to a trusted applications path that caused a timeout error when users defined a matching Path value without wildcards. For comprehensive details of these fixes and changes, users are directed to consult the 7.17.4 release notes.
May 24, 2022 184 words in the original blog post.
Fram Souza's guide outlines the process of deploying Elastic Cloud on Kubernetes (ECK) using Terraform on Google Cloud Platform (GCP), emphasizing the simplicity of setting up a Kubernetes cluster with ECK by executing just three commands. The tutorial involves creating a Google Kubernetes Engine (GKE) cluster with a node pool consisting of three nodes, deploying the ECK operator, and establishing an Elasticsearch cluster with three nodes alongside a Kibana instance. The prerequisites include having Terraform and gcloud commands installed, and the setup involves authenticating with Google Cloud, configuring environment variables, and running a sequence of Terraform commands to initialize, plan, and apply the infrastructure changes. The guide provides specific instructions on accessing the Kubernetes cluster and Kibana service, and concludes with cleanup instructions using Terraform destroy, encouraging further exploration of ECK in production environments and with Helm.
May 24, 2022 443 words in the original blog post.
ThoughtLab's cybersecurity benchmark study indicates that cybersecurity is at a pivotal moment, with public sector organizations facing increased complexities due to trends like digital transformation and remote work. Despite 60% of these organizations being at a mid-implementation level of cybersecurity maturity, 34% still feel unprepared for evolving threats. Key areas for improvement include addressing system misconfigurations, outsourcing security operations centers and threat intelligence due to resource constraints, and enhancing security information and event management (SIEM) with machine learning capabilities. Public sector entities are also encouraged to harden operational technology attack surfaces and consolidate tools into platforms for greater efficiency. Emphasizing human-centric cybersecurity—through awareness, training, and community engagement—can lead to fewer breaches and quicker response times. The report underscores the importance of strategic investments and resource optimization to navigate the new era of digital risk.
May 24, 2022 995 words in the original blog post.
The text provides a comprehensive guide on setting up an Elasticsearch Cluster on Kubernetes (ECK) environment optimized for production. It covers various components and configurations necessary for deployment, including dedicated stack monitoring, Elasticsearch autoscaling, and the use of nodeAffinity and nodeSelector for resource allocation. The setup also incorporates advanced features such as SAML authentication with Auth0, a hot-warm-cold-frozen architecture, SSL certificate management via cert-manager with Let's Encrypt, and external DNS integration with Cloudflare. The guide emphasizes the importance of following the correct execution order for commands and provides detailed instructions for deploying resources such as ElasticSearch, Kibana, and fleet-server. Additionally, it mentions the use of esrally for autoscaling validation and benchmarking, highlighting essential configurations and tools to ensure a secure and efficient production environment.
May 23, 2022 685 words in the original blog post.
The article by David Kyle provides a detailed guide on deploying a sentiment analysis model using natural language processing (NLP) to evaluate the sentiment of comments as either positive or negative. The process involves using a pre-trained sentiment analysis model from Hugging Face, deployed to Elasticsearch, to analyze customer reviews from the 2015 Yelp Dataset Challenge. The deployment process is facilitated by the Eland docker agent and involves setting up an ingest pipeline in Kibana to classify reviews. The article illustrates the procedure with examples, showing how comments are labeled with predicted sentiment values and their associated probabilities. It highlights the utility of sentiment analysis in understanding customer feedback, with a practical example revealing that approximately 44% of the analyzed Yelp reviews are positive, although the model mislabels a small fraction. The guide encourages experimentation with NLP features in Elastic Stack, promoting a 14-day free trial to explore further applications, such as text embeddings and named entity recognition.
May 20, 2022 1,041 words in the original blog post.
Elastic and AWS, once considered competitors, have transformed their relationship into a collaborative partnership aimed at enhancing the availability and accessibility of Elastic Cloud on AWS for their joint customers. The expanded collaboration involves improvements in user sign-up and onboarding processes, simplified data ingestion, new marketing initiatives, and increased AWS competencies and qualifications. Elastic CEO Ash Kulkarni described this partnership as mutually beneficial, highlighting its potential to leverage AWS's extensive global reach and service offerings. The article underscores the strategic alignment between the two companies to create a seamless experience for users and drive growth.
May 20, 2022 206 words in the original blog post.
The release of Elastic Stack 8.0 introduced the capability to integrate PyTorch machine learning models into Elasticsearch, facilitating advanced natural language processing (NLP) applications. This enhancement allows for improved information extraction, text classification, and search relevance through dense vectors and approximate nearest neighbor search. The blog series provides step-by-step guidance on deploying various PyTorch NLP models, such as text embeddings, vector search, named entity recognition (NER), and sentiment analysis, using prebuilt models from the Hugging Face model hub. The series emphasizes the importance of starting with a clear use case and understanding the text data to process, while also outlining the technical prerequisites like an Elasticsearch cluster with version 8.0 or higher and specific plugins. It suggests using a free 14-day trial on Elastic Cloud, which supports deploying one or two examples at a time, to facilitate hands-on learning.
May 20, 2022 347 words in the original blog post.
In a detailed exploration of deploying Named Entity Recognition (NER) using Elasticsearch, the text guides readers through the process of utilizing an NER model to extract entities, such as people and locations, from unstructured text. The example uses a model from Hugging Face, deployed through Eland, to analyze the characters and settings in Les Misérables. By running the model via Docker, users can identify entities in text fields using the _infer API and integrate this into an ingest pipeline with Elasticsearch, enabling bulk inference. The process includes mapping text fields, configuring a pipeline in Kibana, and using scripting to categorize entities. Readers are shown how to visualize the data with tag clouds, and how to optimize performance by adjusting thread settings for better throughput and latency. The text also highlights the broader applicability of NLP in Elasticsearch, with additional tasks like text classification and sentiment analysis, encouraging users to explore further with Elastic Stack's new NLP features.
May 20, 2022 1,748 words in the original blog post.
In the rapidly evolving landscape of capital markets, speed and data management are crucial for success, as firms face increased data volumes and complex technological demands. Elastic provides tools that enable market participants to efficiently consume, track, secure, manage, and enrich data, thereby enhancing IT efficiency and fostering a culture of risk excellence. The integration of real-time telemetry data with business information allows firms to better understand and address performance issues, improving trade execution and client services. As regulatory activity intensifies, particularly concerning AI-driven models, firms are focusing on data governance and risk mitigation, leveraging Elastic to meet compliance and manage risks effectively. Additionally, the shift towards cloud-based services is transforming trading operations, with both buy-side and sell-side firms increasingly adopting cloud technologies for analytics and data management. Elastic Cloud supports this transition by offering scalable solutions that enhance data visibility, enabling financial institutions to turn data into a strategic asset.
May 19, 2022 1,121 words in the original blog post.
Elastic has expanded its collaboration with AWS to enhance the accessibility and integration of Elastic Cloud on AWS, aiming to provide seamless data search, analysis, and protection for shared customers. This partnership focuses on streamlining signup and onboarding processes, simplifying data ingestion, and launching new go-to-market strategies, while also leveraging AWS's global reach and services. Elastic has achieved multiple AWS validated qualifications, demonstrating their specialized expertise and customer success. The collaboration emphasizes delivering a consistent customer experience with cloud-native features designed to optimize cost and performance at scale. Elastic and AWS are committed to empowering innovation and collaboration, particularly in cybersecurity, as evidenced by their work with the Maryland Innovation and Security Institute. Elastic also offers a 7-day free trial and competitive pricing on AWS Marketplace to further benefit customers.
May 19, 2022 536 words in the original blog post.
BPFDoor is a sophisticated backdoor payload targeting Linux systems, designed to enable re-entry into compromised environments, as detailed by the Elastic Security Intelligence & Analytics Team. This malware has been active for over five years, indicating that its operators have remained undetected in numerous networks, utilizing a network of VPS servers and compromised routers in Taiwan to act as a VPN. The research delves into the payload's lifecycle, the use of BPF filters for evasion, and offers insights into detection methods and the complexity of its loader. The Elastic team provides indicators of compromise and emphasizes the importance of monitoring organizational workloads effectively, offering tools like a 14-day trial of Elastic Cloud or a free version of the Elastic Stack for enhanced security.
May 18, 2022 292 words in the original blog post.
Telecom providers are at a pivotal moment as they aim to monetize their 5G networks, which have required significant investment. Unified observability is essential for leveraging data to unlock 5G monetization opportunities, such as network slicing and Network Data Analytics Functions (NWDAF). Network slicing, estimated to be a USD 200 billion opportunity, allows telecom providers to offer tailored connectivity and data services. NWDAF enables standardized data management and automation in network operations, crucial for managing the complexity and volume of 5G-generated data. Despite the potential, telecom companies face challenges like underutilization of data resources and data silos, with a small percentage effectively monetizing customer data. A unified observability approach can overcome these hurdles by integrating security measures and employing machine learning for automation, thereby enhancing network performance, reducing costs, and driving innovation. As 5G networks evolve, telecom providers must address these data challenges and seek partnerships to scale their offerings, ensuring agility and avoiding vendor lock-ins to successfully design next-generation telecom services.
May 18, 2022 1,038 words in the original blog post.
Elastic Maps' 8.1.0 release now supports a Machine Learning Anomalies Layer, allowing users to view geographical anomalies detected by ML jobs directly on maps. This feature is particularly useful for analyzing data like the General Transit Feed Specification (GTFS) from San Antonio, TX, which includes real-time vehicle position updates. Users can create anomaly detection jobs in Kibana with the lat_long function to identify unusual geographic locations for vehicles, which may signal issues or delays. Once the job results are available, users can visualize them on Elastic Maps by adding an ML Anomalies layer that displays actual, typical, and actual-to-typical positions, color-coded by anomaly severity. Additionally, users can filter anomalies by time frame or severity score, facilitating a focused analysis of significant deviations from typical vehicle patterns. The integration also allows seamless navigation from the Anomaly Explorer view in Elastic Machine Learning to Elastic Maps, enhancing the user's ability to analyze and investigate anomalies in detail.
May 17, 2022 961 words in the original blog post.
Cybersecurity is increasingly challenged by the proliferation of cloud tools and the diverse data they generate, necessitating improved search technology for better threat detection and asset visibility. Many enterprises lack a comprehensive view of their digital assets, but advanced search capabilities, using machine learning and natural language processing, can fill these gaps by enabling organizations to query their environment and data more effectively. Security teams can leverage these tools to identify vulnerabilities, detect anomalous behavior, and limit the spread of malware, as demonstrated in the case of the Log4j vulnerability. Robust search applications allow for rapid data analysis, enabling quick response to threats and the deployment of necessary patches. As attackers continually target widely used resources, integrating search into long-term security strategies becomes crucial for staying ahead in the evolving cybersecurity landscape.
May 16, 2022 914 words in the original blog post.
The new PHP client for Elasticsearch 8, developed by Enrico Zimuel, represents a significant update from its predecessor, with a complete architectural redesign that improves developer experience and performance. Adopting PSR standards, the client shifts to a pluggable system using HTTPlug and offers backward compatibility with version 7, maintaining the same APIs while introducing a new response format compliant with the PSR-7 interface. Key features include autocompletion capabilities through the Psalm project, a pluggable architecture that uses the elastic-transport-php library for flexible connectivity options, and enhanced security with default TLS support. The client also supports asynchronous operations by utilizing HTTPlug's Promise interface, reducing both codebase size and memory usage significantly compared to the previous version. These updates aim to optimize interaction with Elasticsearch, offering a more efficient, secure, and versatile experience for developers.
May 13, 2022 2,459 words in the original blog post.
Elastic and Microsoft have announced a multi-year strategic partnership aimed at enhancing the capabilities of Elastic Cloud on Azure. This collaboration builds on their existing relationship and focuses on improving search, observability, and security for joint customers by integrating Elastic’s solutions with Azure services. The partnership facilitates faster data insights, seamless deployments, and integrated billing, as well as enhanced capabilities for monitoring and protecting applications and infrastructure. Elastic Cloud on Azure allows users to deploy Elasticsearch within the Azure Portal, leveraging Azure's infrastructure to improve business outcomes through scalable and secure data management. With access to a wide range of integrations and tools, customers can optimize application performance, detect real-time performance issues, and enhance security measures across cloud and on-premises environments. The agreement also enables users to start deployments quickly via the Azure Marketplace, aligning with Microsoft's Azure Consumption Commitment and offering expanded regional coverage.
May 11, 2022 1,282 words in the original blog post.
Elastic and Tines have formed a partnership to enhance security operations by combining Elastic's high-speed detection and response capabilities with Tines' no-code automation platform. This collaboration enables security teams to reduce response times and false-positive rates while improving agility and effectiveness. Elastic's scalable approach to data searching, combined with Tines' intuitive automation, supports continuous threat monitoring and incident response. By employing automated workflows, security analysts can efficiently triage alerts, enrich data, and take decisive actions, all while maintaining human oversight through approval processes. The partnership aims to optimize security operations, offering a 14-day trial of Elastic Cloud and access to Tines' Community Edition for workflow automation.
May 11, 2022 1,043 words in the original blog post.
Top global CISOs are addressing rising cybersecurity threats by investing in next-generation technologies like SIEM, EDR, and XDR, as highlighted in a study by ThoughtLab and Elastic. The study, involving 1,200 organizations across 16 countries, underscores a resilience gap between leading organizations and others, urging the latter to accelerate improvements in their cybersecurity strategies. SIEM and IAM are projected to be top investment areas in the next two years, with cloud-native capabilities and advanced analytics becoming crucial for effective threat detection. The increased adoption of cloud technologies necessitates robust security measures, as misconfigurations are anticipated to become a leading cause of breaches. Advanced organizations are also focusing on security as a data challenge, enhancing continuous monitoring, anomaly detection, and data security practices. Despite a talent shortage, organizations are investing in upskilling their cybersecurity teams to mitigate risks like phishing and human error. CISOs are playing a more strategic role, emphasizing collaboration across the C-Suite to bolster security efforts.
May 10, 2022 1,495 words in the original blog post.
Adrienne Cohen and Isabelle Li, Directors of Partner Marketing at Elastic, have been recognized in the 2022 CRN Women of the Channel list for their outstanding work in cloud-partner marketing with Microsoft and Google. Their efforts have significantly enhanced customer experiences by integrating Elastic Cloud services into platforms like Azure and Google Cloud, making access and support more seamless for users. Both leaders emphasize the importance of building strong, trust-based relationships with cloud partners to prioritize customer value and drive Elastic’s cloud-first strategy. Being named to the CRN list is both a personal and professional honor for them, reflecting their contributions to advancing the channel and fostering a supportive community among peers in the industry.
May 09, 2022 884 words in the original blog post.
In the realm of cloud security, shell evasion tactics pose a significant threat as cybercriminals use stealthy techniques to bypass detection, often by exploiting command and script interpreters to gain unauthorized access to sensitive data. These attacks can involve malicious shell scripts that circumvent anti-malware systems by disguising as benign activities, making detection challenging. The article highlights the role of Elastic Security 8.2 in enhancing visibility and detection of such threats by introducing GTFOBin shell evasion rules, allowing organizations to monitor suspicious activities across Linux libraries. The new detection rules help identify and alert against unauthorized shell activities, providing detailed analysis and response options to safeguard cloud environments. Despite preventive measures, the evolving nature of shell evasion techniques requires continuous monitoring and adaptation to secure cloud operations effectively.
May 09, 2022 1,506 words in the original blog post.
In a detailed report, the Elastic Security Research Team has unveiled insights into the BLISTER loader, a sophisticated cyber campaign first discovered in December 2021, emphasizing the technical intricacies that enable the campaign to evade detection. The report includes a configuration extractor tool designed to aid threat researchers in expanding detection capabilities and provides a comprehensive analysis of the loader's execution phases, nuances, and detection signatures, including YARA signatures. As the team continues to monitor this threat group, they plan to release further updates and reports, while expressing gratitude to the security community for building upon their findings to enhance user safety. Users of Elastic Security are assured protection against known threats through this research, with a free 14-day trial of Elastic Cloud available for new users.
May 06, 2022 328 words in the original blog post.
Breaking down data silos is crucial for enhancing customer experience (CX), as most data remains isolated and underutilized, limiting its influence on customer interactions. Centralized data governance and merging operational with experience data are essential strategies for improving CX, yet many organizations lack a comprehensive data strategy and a centralized digital platform for data management. Effective data architecture and advanced enterprise search can help integrate disparate data sources, enabling companies to leverage machine learning for new insights. The XM Institute's framework, which combines operational data (objective business metrics) with experience data (customer attitudes and perceptions), can reveal hidden data and predict future trends. However, organizational challenges persist, as valuable insights often stem from unexpected sources, requiring leaders to reassess their assumptions and explore diverse data streams to solve business problems and create exceptional customer experiences.
May 05, 2022 1,047 words in the original blog post.
Elastic Enterprise Search 8.2 introduces enhanced functionalities for data ingestion, search, and monitoring, offering developers productivity advantages through built-in capabilities alongside the flexibility of Elastic Stack tools. This release enables seamless interaction with existing Elasticsearch indices using prebuilt tools like relevance tuning and search analytics without the need for data migration. It provides operators with enhanced transparency and governance through audit logs and monitoring features available on Elastic Cloud, ensuring sustained search performance and reliability. Developers can now utilize a shared query language between Elasticsearch and Enterprise Search, facilitating advanced aggregations and complex filtering logic. The update also includes a new search experience library for creating modern search interfaces and customizable SharePoint connector packages. Elastic Cloud users can access these features directly, with options for new users to explore via trials and training resources.
May 03, 2022 814 words in the original blog post.
As data volumes increase and technology interconnects the world, safeguarding sensitive information has become crucial, prompting companies to adhere to various compliance standards such as PCI DSS, TISAX, HIPAA, and FedRAMP. These standards cater to specific industry needs, ensuring data privacy and security across sectors, from healthcare to finance and government. Elastic, a company that provides hosted and self-managed products, has integrated security features to protect organizational information, working closely with regulatory bodies to meet these compliance standards. Their commitment to security is demonstrated through certifications and regular audits, ensuring that they not only comply with industry regulations but also maintain a high level of trust with clients and partners.
May 03, 2022 775 words in the original blog post.
Version 8.2 of Elasticsearch and Kibana introduces a range of new features designed to enhance data exploration and security, including an updated document explorer in Kibana's Discover app that allows users to evaluate data fields and distributions more efficiently. The release also includes improvements to Elasticsearch's vector search capabilities and introduces a new random sampler aggregation in technical preview, which significantly speeds up data aggregations by sampling documents. Elastic Cloud has obtained PCI DSS Level 1 Certification, ensuring enhanced security for payment data, and now supports JSON Web Tokens for API call authorization. Additionally, new Microsoft Azure virtual machine types are available for deployment, offering cost-effective resource configurations. Enhanced observability and alerting features, in partnership with xMatters, improve incident management, and a new French UI is available in Kibana. The update offers unmatched flexibility with lookup runtime fields and encourages users to explore these enhancements through a free trial or by accessing the Elastic Cloud console.
May 03, 2022 1,591 words in the original blog post.
Elastic Security's 8.2 release introduces Cloud Workload Protection capabilities, enhancing cloud security by detecting, preventing, and responding to attacks on workloads across cloud and data centers. This update includes the integration of eBPF for efficient runtime data collection on Linux, which is fundamental for high-performance and secure workload protection. The Elastic Common Schema (ECS) is employed to extend the Linux logical event model, enabling comprehensive data searches and indexing in Elasticsearch. The new Session View feature, now in beta, offers a detailed, terminal-like view of process executions, aiding security practitioners in investigating user and service behaviors on Linux workloads. Session View is seamlessly integrated with Elastic Security workflows, enhancing alert triage and host exploration with rich contextual information. To implement these features, users can follow a detailed setup guide, which includes starting a Cloud Trial or upgrading to Elastic Security 8.2 and configuring Endpoint Security for AWS EC2 instances, ensuring robust workload protection through prebuilt and machine learning rules based on the MITRE framework.
May 03, 2022 821 words in the original blog post.
Elastic 8.2 introduces a range of enhancements across its search-powered solutions, providing users with greater flexibility and speed in building seamless search experiences. This release includes improvements such as tail-based sampling for better application performance monitoring, advanced Elasticsearch query capabilities for Enterprise Search, and vector search enhancements for faster and more precise search results. Additionally, Elastic Security 8.2 offers new investigation guides and contextual alerts to improve security analysis workflows. The update also enhances data exploration in Kibana and maintains Elastic Cloud's high security standards with new certifications. Elastic 8.2 is available on Elastic Cloud, with options for a free trial or self-managed version.
May 03, 2022 1,573 words in the original blog post.
Elastic 8.2 introduces a beta version of the Elasticsearch Search API for App Search, providing enhanced flexibility and power by allowing users to execute free-form Elasticsearch queries directly on App Search document indices. This new API facilitates various advanced query functionalities such as counting documents without retrieving the full search results payload, grouping document counts by specified fields, searching for documents similar to a particular one, and applying custom functions to calculate document scores. Additionally, the API enables the retrieval of document subsets without scoring and supports exact match searches through workarounds like runtime fields and script queries. Although runtime fields are less performant compared to indexed fields, they offer a temporary solution for certain search requirements. The update also includes the Search Explain API, which reveals the Elasticsearch queries generated by App Search, allowing users to understand and customize their search logic further. These tools aim to enhance the search experience by providing more granular control and insights into query processing, encouraging users to experiment with Elastic Cloud's free trial and share feedback.
May 03, 2022 1,979 words in the original blog post.
Elastic Security 8.2 introduces enhancements designed to improve the efficiency of security teams by providing deeper insights and greater visibility into potential threats. The release features rich alert contextualization, osquery host inspection directly from alerts, new investigation guides, and the general availability of threat intelligence. It offers improved user activity monitoring to combat insider threats and privilege abuse, alongside Session View for examining process executions on Linux systems. Analysts benefit from accelerated alert triage with enriched context, enabling more precise identification of alerts that require attention. The update also includes new investigation guides with expert advice, extending support for detecting threats against Windows systems, which aids both junior and experienced analysts. The general availability of threat intelligence allows organizations to leverage multiple sources for event enrichment and automated detection. Enhanced endpoint behavior protections and the ability to use custom blocklists further bolster defenses against sophisticated adversaries. Additionally, the update includes prebuilt data integrations and detection rules mapped to the MITRE ATT&CK framework, helping organizations detect and respond to a wide array of attack techniques.
May 03, 2022 1,418 words in the original blog post.
Elastic has announced that its Elastic Cloud services are now compliant with the Payment Card Industry Data Security Standard (PCI DSS), allowing cardholder data to be stored across all Elastic Cloud regions in a secure manner. PCI DSS provides security standards for organizations that handle cardholder data, requiring robust access controls, vulnerability management, and regular network monitoring. Elastic achieved this compliance after a Level 1 Service Provider assessment by a third-party auditor, as recognized by the PCI Security Standards Committee’s Cloud Computing Guidelines. Customers can request the PCI Responsibility Matrix and the PCI DSS Attestation of Compliance (AOC), which demonstrate Elastic's adherence to security best practices. These documents outline the shared compliance responsibilities between Elastic and its customers, and customers are encouraged to contact their Account Executive for further details if their use case involves PCI DSS compliance.
May 03, 2022 288 words in the original blog post.
Elastic Observability 8.2 introduces advanced features aimed at enhancing visibility and efficiency in cloud-native environments, with key updates including tail-based sampling for distributed tracing and enhanced support for AWS services. Tail-based sampling allows for more strategic data collection by deciding which transactions to sample after completion, offering granular control to capture significant transactions based on criteria like duration and outcome. Additionally, the release improves serverless visibility by enabling the collection of traces from AWS Lambda functions and simplifies data ingestion from various AWS sources, enhancing overall observability. The update also introduces new synthetic testing infrastructure in beta and supports compressed spans to optimize network transfer and storage costs for data-intensive applications. These advancements are designed to help DevOps and SRE teams eliminate blind spots, reduce total ownership costs, and accelerate troubleshooting in complex, high-volume distributed systems, while continuing to enhance alerting and management capabilities.
May 03, 2022 1,472 words in the original blog post.