bash ./run-demo.shthen demo the data rolling into kibana...
then to simulate someone doing potential bad things to a system, we'll just copy an executable in sbin...
bash ./demo2.shnow go and search for badactor and find the record of a new file being introduced
then change it again...
bash ./demo3.shand show a second line recorded that details a change in /sbin/ to the same file.