Does elasticsearch support output streams similar to Graylog as shown here?


The use case is forwarding specific events to a commercial SIEM solution. Happy for suggestions how to achieve this.

I moved your question to #logstash as elasticsearch does not push any data to any external system unless you are using alerting feature (commercial license) which can call an http endpoint.

Brilliant, thank you. I think thats answered my question with a simple "no" :slight_smile:

Still interested to hear people opinion using logstash to push to SIEM.


The streams you describe seem to map quite closely to the type of logic you would implement in Logstash. Logstash has a variety of outputs that you can use to push data to SIEMs.

