Hello everyone !
i am very new to elastic and while going through the documentation i was not able to find somethings ,so if possible help me understand these and also provide the documentation link so i can verify (in prepective of SIEM)
q1. basic standalone & distributed architecture with main components and internal communication ports ? is their any refrence image of the architecture showing all components and ports (i have already seen hot/frozen architecture and it is not the basic one also it dosnt have the port numbers // also gone through ingest architecture in documentation /// componets i know are kibana -Elasticsearch-logstash-fleet-xpack if possible explain them and give me a basic diagram from documentation
q2. while reading about logstash and elastic agent i am not able to understand why are the major advantages of using logstash over the elastic agent or where the elastic agent should be used & where logstash (gone through ingest architecture documentation and got to know thoes 4 points like PQ ,proxy and etc are those only points but their also it is mentioned the used when we tranfer data from eelastic agent ,what if dont use elastic agent
q3. problem in understanding fleet & fleet server like ? first it seemed that fleet is on kibana but it is the web-ui only so if asked where is fleet as a component so the ans would be kibana or Elasticsearch & also the clarification /// dif between fleet server and standalone like why to use each or which one to prefer when
q4. what are the recommended os for slef mange like ubuntu or windows or mac (already gone through support matrix pdf ) but it dosnt state which are recommended it just tell which are supported which are not
q5. lets say i have to take logs from checkpoint firewall and i find it hard to write filter in logstash so i decide to use elastic agent and decided to use the checkpoint integration so my question is where should be elastic agent installed on seprate vm or windows or on the vm which is running Elasticsearch ? and in that case what would be the architecture like