Hi thanks for your reply. There's a lot there for me to go and learn/read.
You can still populate the
output.elasticsearch.X settings. When using cloud, only the hostname setting will not be useable.
output.elasticsearch.indices get disabled if ILM is enabled, because ILM requires you to have a write alias.
Oh right, so i can remove
Do you want to use ILM for all indices, or not at all?
I think so, I want to keep the index for about 90 days then i can allow old data to drop off.
My use case is to "make AD searchable". I am indexing AD Users and Computers on a 4 hourly schedule. The data is generated with a Powershell script writing out to a JSON file, picked up by Filebeat for shipping. I just now need to convert my field names to be ECS compatible. I want to get it ready so others in the community can use it also, as i feel there is a good use case for it. AD data can then be enriched and correlated with Windows Security log data and other ECS compatible data. I'd be happy to work on this with others if you're interested.
This provides some great search and visuals for AD like
- How many user, or computers
- List the users with passwords about to expire
- Show me inactive users etc.
- Show me new users created or deleted today