Hi
Im in a little bit of hurry.
We are in a procurement process, handling the solution today 23.59.
The customer have the demand to monitor Windows OS logs and especially the Security logs.
I've been looking at Winlogbeat with Elastic Search and Kibana and it looks really good.
But I'm not sure of the infrastructure, can you please help me with that?
My guess its enough with one server with a lots of RAM and some CPU? Thinking of both cloud and on-prem.
And of course, what about support to Windows 10? It will be mostly Windows 7 in the beginning but around dec-jan they will be migrated to Windows 10.
And what about x-pack, do I really need that, what's the price?
5500 Windows 10 PCs, only shipping the Security log.
I'm guessing about 165 Gb data/day, storing 31 days > 4-5Tb of data.
We always recommend testing such. That way you can get a base line for how well a single node cluster will cope with the number of shards versus the resources allocated.
What we have to go on thus far is winlogbeat-security-* aptly named daily indices, up to 200GB per day.
With a retention period of 31 days, 6.2TB
So say you want to resource performantly keep somewhere between 500-1TB of data per data node.
What do you want to gain from X-Pack. I personally believe x-pack is cool, thus would recommend alerting, monitoring, security, and later on machine learning to do cool things find out a baseline for how many windows laptops you are collecting events from who's mac addresses were residing in one location on a given day the same day every week and send an alert when things start to look anomalous.
8. https://www.elastic.co/products/x-pack
Pricing here but also all the above is an insight to the depth of support you may get when you get a subscription with us
9. https://www.elastic.co/subscriptions
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.