We are planning to use Wazuh for some of our monitoring needs. Wazuh does not support ECS. Now, I plan to make the Wazuh data ECS compliant for better monitoring!
My question is, which of the following would be a better option and why? What impact would they have from a performance perspective?
- Create an Alias for all Wazuh fields
- Copy the Wazuh fields into ECS compliant field names
A thing to consider is that Wazuh logs are quite varied and will probably need to create a table for well over 20-30 fields! Each log line will have a minimum of 10-15 fields. So adding a new field would probably double the storage needs, but would aliases lead to a performace hit when you have like Billions of messages?