I checked the documentation and using the logstash outputs it is not possible to use separate fleet managed agents with logstash output to different clusters.
But what about the integrations?
Lets imagine for big deployment there are (for simplicity) following 3 clusters:
- user cluster
- metrics cluster
- logs cluster
Users are accessing the Kibana app in user cluster and want to browse logs and metrics using the cross cluster search. ... OK fine using custom patterns, dashboards, ...
But how does integrations (and its assets) solve it? Is it really necessary to install integrations to both user and metrics/monitoring clusters and after that alter the dashboards, patterns to use another cluster? Or is there a better (not such a terrible) way to manage it?