Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

replace beats with fluentbit #102

Closed
mmguero opened this issue Jun 8, 2022 · 3 comments
Closed

replace beats with fluentbit #102

mmguero opened this issue Jun 8, 2022 · 3 comments
Assignees
Labels
beats Relating to Malcolm's use of Beats enhancement New feature or request logstash Relating to Malcolm's use of Logstash research Research or proof-of-concept for an idea sensor For issues dealing with the Hedgehog OS capture sensor

Comments

@mmguero
Copy link
Collaborator

mmguero commented Jun 8, 2022

As we're not using Elastic any more (replaced by OpenSearch), using beats might not be the best choice. Replacing it with fluentbit would probably be a better option.

@mmguero mmguero added beats Relating to Malcolm's use of Beats logstash Relating to Malcolm's use of Logstash sensor For issues dealing with the Hedgehog OS capture sensor labels Jun 8, 2022
@mmguero mmguero self-assigned this Jun 8, 2022
@mmguero mmguero added enhancement New feature or request research Research or proof-of-concept for an idea labels Jun 8, 2022
@mmguero
Copy link
Collaborator Author

mmguero commented Jun 8, 2022

See #103 as well.

@mmguero
Copy link
Collaborator Author

mmguero commented Jun 30, 2022

At this point all beats have been replaced in my development branch (mmguero-dev/Malcolm@development) except for filebeat. Where I'm just using basic filebeat operations to send to logstash, I think that's where we'll leave it for now. All the "heavy lifting" of sensor metrics from hedgehog is done by fluent-bit now. honestly as long as we're still using logstash (#103) it will make most sense to use filebeat as well, if only as a bridge between fluent-bit and logstash (using the TCP input) as they don't directly connect at the moment.

This was referenced Jul 12, 2022
@mmguero
Copy link
Collaborator Author

mmguero commented Jul 12, 2022

this is done to the extent it will be (until we take care of #103) so closing for now. filebeat is the only "beat" used now, and it's the 7.10.2 apache licensed version.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
beats Relating to Malcolm's use of Beats enhancement New feature or request logstash Relating to Malcolm's use of Logstash research Research or proof-of-concept for an idea sensor For issues dealing with the Hedgehog OS capture sensor
Projects
Status: Released
Development

No branches or pull requests

1 participant