seeing @wazuh grow from just an EDR/HIDS to full fledged SIEM with XDR/HIDS is just awesome!
don't have to focus on deploying elasticsearch/opendistro/opensearch
And if you are a nerd like me, you can still get this in your *whatever* stack you are using
Was thinking that or... IDK. OpenDistro??
Splunk free is great, until you're over the limt and then... well... it's not affordable to most mom and pop orgs.
KubeDB provides various Elasticsearch distributions (ElasticStack, OpenSearch, SearchGuard, OpenDistro ) support under the Elasticsearch CR of KubeDB. Here is how to Run & Manage OpenSearch in Google Kubernetes Engine (GKE) Using KubeDB.
Visit:blog.byte.builders/post/gke-โฆ
fluentdใงใญใฐ้ไฟกใใฆใใณใณใใใใชใใซใใใใ้ไฟกใงใใชใใชใฃใใ
fluent-plugin-elasticsearchใใใopendistro for elasticsearchใซ้ไฟกใงใใชใใชใฃใใใใใๆฆไบใฎไฝๆณขใๆใใฌๅฝขใงใใใใ๏ผ่พใ
stackoverflow.com/questions/โฆ
7.13 and up will not be compatible with opendistro/opensearch going forward, so that would include the elastic agent you mentioned if i'm reading all this right
elastic.co/guide/en/beats/liโฆ
They made licensing changes back in 2018 to combat AWS running managed services, and all new features since are under Elastic. AWS forked source in retaliation (OpenDistro).
The recent changes adopt dual license w Elastic or SSPL (MongoDBโs newly created licensing scheme)
New benchmarking of #ann#vectorsearch implementation by .@Pinecone_io engineering comparing with Elasticsearch, OpenDistro and GSI -- pinecone.io/learn/bert-searcโฆ Happy to have helped with reading the drafts of this article.