Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend

This course is coming soon. It is not yet open for enrollment, and no payment is taken.

The outline and outcomes below reflect what this course will cover. Check back soon.

Coming soonIntermediate

Elastic Security for Analysts

Investigate with KQL, Discover and the Timeline.

By LearnDefend Security Team · SOC & Blue Team

About this course

Use the Elastic Stack the way an analyst does: KQL search, aggregations and the date histogram, the Alerts table and Timeline correlation — transferable SIEM reasoning, complementing the hands-on Elastic Tool Academy.

What you'll learn

  • Search and filter documents with KQL.
  • Aggregate and chart to reveal patterns.
  • Correlate an incident on the Timeline.

Course outline

  1. 1The Elastic Stack & KQL
  2. 2Aggregations & visualizations
  3. 3Alerts & Timeline
  4. 4Final investigation

Prerequisites

  • SOC fundamentals; log-reading comfort.
Elastic Security for Analysts | LearnDefend