We are using platinum subscription for our "elastic" stack from "elastic.co" and we are informed that they do not support "immutable indices" for our subscription. We are using the elasticsearch version 7.17.5 with our agents - file, audit and metric beats as 7.10.2. Can someone help us with implementing the "immutable indices" with what we have now?
Once a index is created in Kibana, we don't want any one to modify the index or the document or a record in the logs that flows into Kibana.
Now the normal index will change to "immutable" - no one can change anything , even delete the index.
Does this configuration needs to be done in the "elasticsearch.yml" settings? or what steps do I need to follow to make any index an "immutable index"?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.