Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: James Bonifield

Rating No ratings yet

Security teams rely on telemetry—the continuous stream of logs, events, metrics, and signals that reveal what’s happening across systems, endpoints, and cloud services. But that data doesn’t organize itself. It has to be collected, normalized, enriched, and secured before it becomes useful. That’s where data engineering comes in. In this hands-on guide, cybersecurity engineer James Bonifield teaches you how to design and build scalable, secure data pipelines using free, open source tools such as Filebeat, Logstash, Redis, Kafka, and Elasticsearch and more. You’ll learn how to collect telemetry from Windows including Sysmon and PowerShell events, Linux files and syslog, and streaming data from network and security appliances. You’ll then transform it into structured formats, secure it in transit, and automate your deployments using Ansible.

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 A hands-on field manual for turning scattered security telemetry into a governed, queryable pipeline using only free and open-source tools. Best for defenders, sysadmins, and engineers who need working infrastructure rather than theory. 【Book Arc】 - **Opening (~0%–10%)**: Frames the core problem—telemetry must be collected, normalized, enriched, and secured before it is useful—and introduces the data engineer's toolkit: JSON, ECS, YAML, and the virtual machine lab setup. - **Early (~10%–32%)**: Builds the trust and transport foundation: a private TLS certificate authority chain, SSH keys, Git-based version control, and the first Filebeat-to-Logstash pipeline with mutual TLS. - **Middle (~32%–50%)**: Extends collection across platforms—Windows event logs via Winlogbeat, Sysmon and PowerShell events, Linux files and syslog, network and appliance streams—plus Kafka as a buffering transport layer. - **Late (~50%–75%)**: Moves from collection to transformation: Logstash filters that rename fields to ECS, parse timestamps, deduplicate, and enrich events before they reach storage. - **Ending (~75%–100%)**: Adds caching and distribution layers (Redis, Memcached) for threat intelligence lookups, then automates the whole deployment with Ansible, including TLS playbooks and drift prevention. 【Key Takeaways】 - **Telemetry is raw material, not intelligence** (Opening): Logs, events, and metrics must be collected, standardized, and enriched before analysts can use them—this framing justifies the entire pipeline. - **Standardization via ECS is the quiet superpower** (Early): Renaming fields like `sip`, `src_ip`, and `sourceip` to `source.ip` means analysts learn one vocabulary instead of one per tool. - **TLS is infrastructure, not an afterthought** (Early): The book builds a root CA, intermediate CA, and signed certificates before any data flows, treating encrypted transport as a prerequisite. - **Git and Ansible turn a pile of configs into a reproducible system** (Early–Late): Version control provides rollback and disaster recovery; Ansible playbooks make deployment repeatable and drift-resistant. - **Collection must span Windows, Linux, and network appliances** (Middle): Filebeat, Winlogbeat, Sysmon, and PowerShell logging each require distinct configuration and tuning—BITS logs, for example, need aggressive filtering to be useful. - **Kafka decouples producers from consumers** (Middle): It buffers and load-balances between collection and processing, with directional tagging to preserve data lineage. - **Caching accelerates threat intelligence lookups** (Late): Redis and Memcached serve as fast key-value stores for indicators, with leader/follower replication and Logstash getters to deduplicate and enrich. - **Automation is the endgame** (Ending): Ansible playbooks for TLS, certificates, and node configuration close the loop from manual setup to repeatable deployment. 【Reading Tips】 - **Deep-read the TLS and Git chapters** even if you have existing infrastructure—the certificate chain and version control workflow underpin every later chapter. - **Skim the tool installation sections** if you already run Filebeat or Logstash; focus instead on the configuration patterns and field-renaming logic. - **Treat the Windows chapters as a distinct track**: Sysmon, PowerShell, and BITS logging have their own tuning trade-offs that differ from Linux collection. - **Build the three-VM lab** if possible; the book's clustering, replication, and leader/follower examples assume multiple nodes. - **Use the Ansible chapters as a template**, not a script to copy—adapt the playbook structure to your own environment and certificate naming. 【Coverage Limits】 The excerpts cover the book's structure, foundational chapters, and tool configurations in detail, but do not include full code listings, every chapter's content, or the complete Ansible playbooks. Specific command syntax and configuration file contents are only partially represented.
Page 9
th Memcached Configuring the Cyber Threat Intelligence Node Configuring the Data Node Preventing Drift Handling Analyst-Submitted Indicator Data Going Beyond...
View in text
Excerpt 2
❻ [ca_root] nsComment = OpenSSL Certificate for Root CA subjectKeyIdentifier = hash authorityKeyIdentifier = keyid:always,issuer basicConstraints = critical,...
View in text
Excerpt 3
.flex.cert.pem tls/certs/filebeat.local.flex.cert.pem: OK As we have a valid certificate with both the clientAuth and serverAuth extensions, we can begin con...
View in text
Excerpt 4
using the intermediate CA to create the signed certificate. Alternatively, you may use the wildcard certificate and key from Chapter 6. Elasticsearch, which...
View in text
Excerpt 5
astic Agent use pipelines slightly differently, even though the agent performs many of the same functions behind the scenes using Beats. For instance, Packet...
View in text
Excerpt 6
you installed Rsyslog and learned its configuration layout. You explored global settings, inputs and outputs, templates, and rulesets. You also configured Lo...
View in text
Excerpt 7
"log" => { "syslog" => { "priority" => "191" } "syslog_timestamp" => "Jan 19 17:22:43", While effective, this query is clunky for analysts, who must know the...
View in text
Excerpt 8
s, suspicious user logins, or certain database transactions. In the shopping world, you’ll find purchasing topics used by both fulfillment software and real-...
View in text
Tags
AI categories
CybersecurityData EngineeringDevOps
ISBN: 1718504020
Publisher: No Starch Press
Publish Year: 2025
Language: English
Pages: 449
File Format: PDF
File Size: 6.1 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…