# Elasticsearch - get logs from DMZ

**URL:** <https://discuss.elastic.co/t/elasticsearch-get-logs-from-dmz/332901>\
**Category:** Elasticsearch\
**Created:** [May 9, 2023, 9:36am UTC](https://discuss.elastic.co/t/elasticsearch-get-logs-from-dmz/332901 "2023-05-09T09:36:13Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sharon\_Hacham](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharon_hacham/32/105161_2.png) [@Sharon\_Hacham](https://discuss.elastic.co/u/Sharon_Hacham)\
**Post date:** [May 9, 2023, 9:36am UTC](https://discuss.elastic.co/t/elasticsearch-get-logs-from-dmz/332901/1 "2023-05-09T09:36:14Z")

</div>

Hi ,  
we have Elasticsearch cluster and now we want to stream logs from DMZ environment to there which isn't allowed by InfoSec purpose. Only allowed method of pull from the DMZ.  
What's the preferred option in such case ?  
we thought of several options and would like to get what's the best practice -

- Asynchronous mechanism - send the logs to some queue / Container / Kafka and pull it from there - lot of components involved and performance issues

- Cross Site Replication - create ECK or other deployment of Elasticsearch on the DMZ and send the logs there , and later replicate the indices to the original cluster - is that approach correct or it can have performance issues ? can you control the direction of where to replicate from ? can you view the logs in the target cluster after some time ?

- Create ECK or other deployment of Elasticsearch on the DMZ and Have Kibana look at the remote cluster logs using Remote Cluster Search , is that something that you can recommend on ?

in the options of creating ECK cluster in the DMZ - can we use a Standard / Basic edition instead of the Enterprise ?

Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 11, 2023, 12:53am UTC](https://discuss.elastic.co/t/elasticsearch-get-logs-from-dmz/332901/2 "2023-05-11T00:53:40Z")

</div>

Pulling from the DMZ is tricky as there's not really a native way to do this in the stack.

You could definitely setup 2 clusters and then tell the DMZ one to replicate that to the external one, as CCR can be one way. CCS might also tick this box as you can run your searches on the non-DMZ cluster and then it pulls results from the DMZ one.

---

<div class="post-metadata">

**Author:** ![Sharon\_Hacham](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharon_hacham/32/105161_2.png) [@Sharon\_Hacham](https://discuss.elastic.co/u/Sharon_Hacham)\
**Post date:** [May 11, 2023, 6:11am UTC](https://discuss.elastic.co/t/elasticsearch-get-logs-from-dmz/332901/3 "2023-05-11T06:11:06Z")

</div>

Thanks for replying ,  
we are thinking of the cross site search option , having Kibana look at the indices of the remote cluster on the DMZ ... we understand that Basic version of the Elasticsearch can be installed on the DMZ for that purpose of storing the data and the nodes to be configured as remote\_cluster\_client  
Do you find any issues with that ?  
Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 11, 2023, 6:56am UTC](https://discuss.elastic.co/t/elasticsearch-get-logs-from-dmz/332901/4 "2023-05-11T06:56:07Z")

</div>

You should be good then 🙂

---

<div class="post-metadata">

**Author:** ![Sharon\_Hacham](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharon_hacham/32/105161_2.png) [@Sharon\_Hacham](https://discuss.elastic.co/u/Sharon_Hacham)\
**Post date:** [May 11, 2023, 9:28am UTC](https://discuss.elastic.co/t/elasticsearch-get-logs-from-dmz/332901/5 "2023-05-11T09:28:48Z")

</div>

thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 8, 2023, 9:29am UTC](https://discuss.elastic.co/t/elasticsearch-get-logs-from-dmz/332901/6 "2023-06-08T09:29:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
