This course is coming soon. It is not yet open for enrollment, and no payment is taken.
The outline and outcomes below reflect what this course will cover. Check back soon.
Coming soonIntermediate
Elastic Security for Analysts
Investigate with KQL, Discover and the Timeline.
By LearnDefend Security Team · SOC & Blue Team
About this course
Use the Elastic Stack the way an analyst does: KQL search, aggregations and the date histogram, the Alerts table and Timeline correlation — transferable SIEM reasoning, complementing the hands-on Elastic Tool Academy.
What you'll learn
- Search and filter documents with KQL.
- Aggregate and chart to reveal patterns.
- Correlate an incident on the Timeline.
Course outline
- 1The Elastic Stack & KQL
- 2Aggregations & visualizations
- 3Alerts & Timeline
- 4Final investigation
Prerequisites
- SOC fundamentals; log-reading comfort.