Increased Elasticsearch Recognizance Scans, (Tue, Aug 19th)

This post was originally published on this site

I noticed an increase in scans that appear to try to identify Elasticsearch instances. Elasticsearch is not a new target. Its ability to easily store and manage JSON data, combined with a simple HTTP API, makes it a convenient tool to store data that is directly accessible from the browser via JavaScript. Elasticsearch has, in particular, been popular for consolidating log data, and the "ELK" (Elasticsearch, Logstash, Kibana) platform has been a very successful standard for open source log management.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.