Elastic Band
Like a lot of people, I’m wanting to replace Splunk. To that end I’ve been looking into Elasticsearch.
My prerequisites are:
- Replace Splunk Enterprise (or Splunk Free) with Elastic and its web UI Kibana;
- Replace Splunk Forwarder with Filebeat;
- Consume syslog over UDP using rsyslog;
- Use TLSv1.2 or better;
- Have an easy to deploy, low-resource client;
- Not use the resource-hungry Logstash.
So I’ve downloaded the RPM’s for the stack I want to use (some extra beats to play with too) and we’ll also install a JDK and a couple of rsyslog modules for later, this was all for CentOS 8.2, but I’ve tested Filebeat at least with SLES 12SP5: