๐ Day 6: Elastic Agent and Fleet Server Introduction
Letโs get started!!!
30-Day SOC Analyst Challenge
๐ Day 6: Elastic Agent and Fleet Server Introduction

Letโs get started!!!
Welcome to Day 6 of the 30-Day SOC Analyst Challenge! ๐ This challenge is designed to provide aspiring SOC analysts with practical, hands-on experience over the course of 30 days. If youโre new here, I highly recommend starting from Day 1 to get the full experience. Today, weโre diving into the world of Elastic Agents and Fleet Servers. Letโs get started! ๐ป
๐ก๏ธ Elastic Agent: A Unified Approach to Data Collection
Imagine youโve installed an agent on 100 Windows machines, but when you log into Kibana to search for PowerShell logs, you realize you forgot to configure the agent to forward those logs to your Elasticsearch instance.
You could manually reconfigure each of the 100 endpoints, or use group policy to update all your endpoints, but thereโs a better way: utilize a Fleet Server to manage all your agents from a centralized location.
What is the Elastic Agent?
The Elastic Agent provides a unified way to monitor logs, metrics, and other types of data. Instead of managing multiple beats for different data types, you can use a single Elastic Agent to collect and forward various logs to your Elasticsearch or Logstash instance. The agent operates based on policies that dictate which logs to forward, which protections to apply, and what integrations to include.
Installation Methods
There are two main installation methods for Elastic Agents:
- Standalone Installation: The agent runs independently, and policies must be configured on each endpoint manually.
- Fleet Managed Installation: This is what weโll be focusing on during this challenge. By using a Fleet Server, you can manage all Elastic Agents from a centralized location, making it easier to update policies, add integrations, and more. ๐
Elastic Agent vs. Beats: Whatโs the Difference?
You might remember our Day 2 blog on the ELK stack, where we introduced Beats โ lightweight data shippers that forward data to Elasticsearch or Logstash. There are six different types of Beats, each specialized in collecting specific types of data. However, with Elastic Agent, you get a unified solution that can replace multiple Beats by collecting various data types using a single agent.
While Beats are still valuable for specific use cases, Elastic Agents offer more flexibility and ease of management, especially when used with a Fleet Server. ๐๏ธ
๐ก Pro Tip: For most use cases, Elastic Agent should suffice. If youโre curious about the full comparison between Beats and Elastic Agent, Iโll provide a link at the end of this post.
๐ก Introducing Fleet Server: Centralized Agent Management
What is a Fleet Server?
A Fleet Server is the component that connects your Elastic Agents to a fleet, enabling centralized management of all your agents. With Fleet, you can easily update agent policies, add new integrations for data ingestion, or change where the agents forward their data (Elasticsearch or Logstash). You can also handle tasks like unenrolling agents or updating them to new versions โ all from a single location. ๐ง
Without a Fleet Server, managing agents across multiple endpoints can become cumbersome, especially if you need to make changes frequently. Fleet Server simplifies this process by offering a streamlined, scalable solution for agent management.

Agent Architecture

Centralized Management for Elastic Agents
Useful links:
Fleet and Elastic Agent overview
๐ฏ Whatโs Next?
In the next session, weโll walk through the process of installing an Elastic Agent and setting up your own Fleet Server, so your endpoints can enroll into a fleet for centralized management. This will give you hands-on experience in configuring and managing Elastic Agents at scale.
Call to Action:
If youโre following along with this challenge, share your progress and thoughts in the comments below! Letโs build this SOC environment together!๐
Connect with Me on LinkedIn! ๐ค
If youโre enjoying this 30 DAY SOC Challenge or want to chat about cybersecurity, cloud computing, or anything tech-related, letโs connect on LinkedIn! I love meeting like-minded professionals and sharing knowledge.
๐ **Jashanpreet Singh on LinkedIn**
Looking forward to connecting with you! ๐
Credits and Special Thanks ๐
A huge shoutout to the MYDFIR YouTube Channel for creating this incredible 30 DAY SOC Challenge and providing top-notch free cybersecurity content for the community! ๐
If youโre passionate about cybersecurity or looking to dive into this field, I highly recommend checking out his channel and website. His content is a goldmine for both beginners and seasoned professionals.
๐ MYDFIR YouTube Channel ๐ MYDFIR Website
Thank you, MYDFIR, for your dedication to making cybersecurity knowledge accessible to everyone! ๐
๋ฉํ๋ฐ์ดํฐ
- post_id
- 815cfd9fe5e7
- slug
- day-6-elastic-agent-and-fleet-server-introduction-30-day-soc-analyst-challenge-815cfd9fe5e7
- url
- https://medium.com/@jashankhaira52/day-6-elastic-agent-and-fleet-server-introduction-30-day-soc-analyst-challenge-815cfd9fe5e7
- canonical_url
- https://medium.com/@jashankhaira52/day-6-elastic-agent-and-fleet-server-introduction-30-day-soc-analyst-challenge-815cfd9fe5e7
- author_url
- https://medium.com/@jashankhaira52
- status
- ok
- fetched_at
- 2026-07-13 06:23:13