How to send data from elasticsearch to another elasticsearch?


i use elasticsearch for wazuh and I need to send data from my local elasticsearch to another elasticseatch.
I want to send only the data that have the level field of a given threshold.
how i do it?



(Mark Walkom) #2

There's a few options;

  • Use Alerting to run a query to match the threshold and then use the webhook to send to the other cluster
  • Use Logstash to do something similar
  • Use remote reindexing to do the same


can you give me details on how each step?
There is documentation that explains how to do?


(Mark Walkom) #4

I'm happy to point you to the relevant documentation.

For the first option; as an idea for the threshold, then the webhook -

For the second;
Input from Elasticsearch and then output

For the last one;

(system) closed #5

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.