Logz.io introduces its AI Agent in Beta, using GenAI to revolutionize observability. The AI Agent simplifies monitoring with automated data analysis and root cause detection, accelerating issue resolution by 3-5x for beta users—marking a critical step toward fully autonomous observability. Today, we’re thrilled to announce the launch of the Logz.io AI Agent, as we blaze a … [Read more...] about Logz.io Clears Way for Autonomous Observability with Logz.io AI Agent
Agent
Improving the event queue in Elastic Agent and Beats
When an output worker is ready to send data, it requests a batch of events from the internal queue. The size of this request is controlled by bulk_max_size, an important output tuning parameter. If bulk_max_size is 100, then the queue will try to provide 100 events for the output worker to send.The queue also has a flush.timeout parameter. When this is zero, the queue will … [Read more...] about Improving the event queue in Elastic Agent and Beats
Using Elastic Agent Performance Presets in 8.12
5. CustomWhile presets are designed to simplify the tuning process for Elastic Agent, the Custom option allows the user to have more granular control over performance. You can still refer to the old guidance provided by Elastic, which is still relevant on Agent as the queue.mem.events are now also configurable. The old guidance, available here, offers practical examples and … [Read more...] about Using Elastic Agent Performance Presets in 8.12
Agent Racoon Backdoor Targets Organizations in Middle East, Africa, and U.S.
Dec 02, 2023Newsroom Organizations in the Middle East, Africa, and the U.S. have been targeted by an unknown threat actor to distribute a new backdoor called Agent Racoon. "This malware family is written using the .NET framework and leverages the domain name service (DNS) protocol to create a covert channel and provide different backdoor functionalities," Palo Alto Networks … [Read more...] about Agent Racoon Backdoor Targets Organizations in Middle East, Africa, and U.S.
Elastic’s contribution: Invokedynamic in the OpenTelemetry Java agent
To overcome the above-mentioned limitations in developing and maintaining auto-instrumentation modules in the OpenTelemetry Java agent, Elastic started contributing its invokedynamic-based instrumentation approach to the OpenTelemetry Java agent in July 2023. To explain the improvement, you should know that in Java, a common approach to do auto-instrumentation of applications … [Read more...] about Elastic’s contribution: Invokedynamic in the OpenTelemetry Java agent
How to combine OpenTelemetry instrumentation with Elastic APM Agent features
Elastic APM supports OpenTelemetry on multiple levels. One easy-to understand scenario, which we previously blogged about, is the direct OpenTelemetry Protocol (OTLP) support in APM Server. This means that you can connect any OpenTelemetry agent to an Elastic APM Server and the APM Server will happily take that data, ingest it into Elasticsearch®, and you can view that … [Read more...] about How to combine OpenTelemetry instrumentation with Elastic APM Agent features
Using the Elastic Agent to monitor Amazon ECS and AWS Fargate with Elastic Observability
Serverless and AWS ECS FargateAWS Fargate is a serverless pay-as-you-go engine used for Amazon Elastic Container Service (ECS) to run Docker containers without having to manage servers or clusters. The goal of Fargate is to containerize your application and specify the OS, CPU and memory, networking, and IAM policies needed for launch. Additionally, AWS Fargate can be used with … [Read more...] about Using the Elastic Agent to monitor Amazon ECS and AWS Fargate with Elastic Observability
Create your own instrumentation with the Java Agent Plugin
TroubleshootingThere are some common problems you might run into when creating your plugin:Still experimental?The OpenTelemetry bridge was added in Elastic APM Java Agent version 1.30.0 — so that is the earliest version you can use this plugin mechanism with — and it was initially added as experimental technology. Depending on which version you are using, you may need to have … [Read more...] about Create your own instrumentation with the Java Agent Plugin
SWEED: Exposing years of Agent Tesla campaigns
Threat Research By Edmund Brumaghin and other Cisco Talos researchers. Executive summary Cisco Talos recently identified a large number of ongoing malware distribution campaigns linked to a threat actor we’re calling “SWEED,” including such notable malware as Formbook, Lokibot and Agent Tesla. Based on our research, SWEED — which has been … [Read more...] about SWEED: Exposing years of Agent Tesla campaigns