Hello, I am completely new to the Elastic Stack and was wondering if the following was possible:
I want to use the Elastic stack for log collection, forensics and as a relay to LogRhythm for specific use cases. I was wondering if this was possible, anybody has tried this and what problems they may have encountered.
A key requirement would be preservation of the original log, ideally we would like to forward specific logs to Logrhythm unprocessed.
Is there a way to forward logs from ELK to Logrhythm? Preferrably raw logs (preserving original source, destination, timestamp, etc).
But Logstash will wrap the original event in some meta fields, like time received and a few other things. So it won't be the original message being forwarded.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.