Demonstration scripts for the Elastic Stack; but can also be used for other purposes.
Look at the following scripts as they are not tied to any specific demo environment and can be used anywhere:
- agent_install+enroll.ps1|sh
- beats_install.ps1|sh
- beats_configure.ps1|sh
- (utilities.ps1|sh)
The ps1 scripts are powershell scripts for Windows and the sh scripts are shell scripts for Linux.
The scripts read a config file called "elastic_stack.config", see the example file.
The rta_ttp.py script can be used to run RTA TTPs from the Elastic Detection Rules project (https://github.com/elastic/detection-rules/tree/main/rta)
The remaining scripts are specific to the skytap demo environment.
None, the scripts are standalone
Copy the scripts to a target system and use as needed.
These scripts are for demonstration purposes only, they do not follow all production deployment recommendations.
Get in touch with me.
No versioning of the script themselves, use as-is. They are writen in a way that they can be used with any post 7.x deployment.
Thorben Jändling <thorbenj@users.noreply.github.com>
AGPL 3
Many colleagues at Elastic.co!