Beats log capture limitation using filebeat, matricbeat and winlogbeat

Hi Team,

Since I am new to Beats and ElasticSearch, I have few query before perfromaing POC on Beats and Elasticsearch for windows and Linux monitoring.
Is possible to capature the log on endpoint and send the capture log at sechdule time to save network bandwidth instead of sending data continuously to Elasticsearch for alerting ?
If yes how much log can be stored locally before sending to logtrash/ElasticSearch ?
As well as share the method to store logs to endpoint and send to centeral monitoring system for alerting and ticketing.

Thanks & Regards
Jai Parkash

Unfortunately, it is not supported by Filebeat.

will it work if we put the logtash in between filebeat and elastic search.
like bastion host in case of network connectivity between your private network server on public cloud.
kindly brief the usages of logtash to complete this issues

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.