Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ECS Normalization to Replace ElastiFlow/Synesis Logstash Pipelines #69

Open
4 tasks done
JaminB opened this issue Jan 29, 2021 · 0 comments
Open
4 tasks done

ECS Normalization to Replace ElastiFlow/Synesis Logstash Pipelines #69

JaminB opened this issue Jan 29, 2021 · 0 comments

Comments

@JaminB
Copy link
Contributor

JaminB commented Jan 29, 2021

ElastiFlow and Synesis are amazing tools, but maintaining compatibility with them has introduced significant technical debt into DynamiteNSM.

We will be migrating away from these LogStash pipelines and instead handle normalization on the agent component itself, allowing for more flexible downstream integration.

NetFlow, IPFix, Zeek, and Suricata will be supported via ECS going forward.

As of 0.8.0 the agent component supports

https://www.elastic.co/guide/en/ecs/current/ecs-using-ecs.html

  • Migration to OpenDistro #72 - Migrate to Open Distro
  • Standarize Default Index Names (Templates/Patterns)
  • Remove ElastiFlow Dashboards
  • Remove Synesis Dashboards
@JaminB JaminB created this issue from a note in DynamiteNSM 1.0 Roadmap (To Do) Jan 29, 2021
@JaminB JaminB self-assigned this Jan 29, 2021
@JaminB JaminB moved this from To Do to Upcoming Release (1.0) in DynamiteNSM 1.0 Roadmap Jan 29, 2021
@JaminB JaminB moved this from In Progress to Completed in DynamiteNSM 1.0 Roadmap Mar 10, 2021
@JaminB JaminB moved this from Completed to Just Shipped in DynamiteNSM 1.0 Roadmap Feb 16, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Development

No branches or pull requests

1 participant