hello
I have just started using elk and playing with it in a small lab. i gave a few question about using it and about architecture
-
if i want to collect event logs from multiple windows servers in my network, do i need to install logstash on every one of them ? is there a way to collect windows events remotely ?
-
i read that there are some plugins and addons to logstash ? where can i fins the list of the available plugins ?
-
i need to collect data that is currently stored in SQL tables, is there a way to collect data from ms sql ?
-
is there a way to use elk to handle snmp traps ? (including mib files to 'translate' the raw data )
-
any other tips for beginners (reading sources and links to get some basic knowledge ..)
thanks for your answers
avishni