Elastic agent - syslog cisco FTD

Hello,

I saw this discussion Syslog to ECK - Elastic Orchestration / Elastic Cloud on Kubernetes (ECK) - Discuss the Elastic Stack and I want to know if there is any progress in this case? The examples in your documentation is only for system metrics.

I try to deploy elastic-agent as a pod inside of my k8s cluster, I want to receive ciscoFTD syslog on port 9001.

What is the correct way to do this?

I don't want to setup a syslog server outside of the k8s cluster and forward the traffic to ES. This can be done but I want to have everything inside of my k8s cluster.

Thanks.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.