Anyone tried or have running a separate logstash instance listening in a secure zone (DMZ) then writing back to elastic in your LAN zone?
I'm getting static from InfoSec on the fact that nxlog traffic source ports are ephemeral. Having a listener inside DMZ that wasn't part of the cluster would be great. I don't want any of the cluster data stored/sharded in the DMZ, though.
-AJ
Logstash only in DMZ?
Logstash only in DMZ?
Andrew J. - Do you even grok?
Re: Logstash only in DMZ?
I guess that works. Would need to switch from om_tcp to om_udp.
Sweet. I'll have to test that out.
Sweet. I'll have to test that out.
Andrew J. - Do you even grok?
Re: Logstash only in DMZ?
Let us know how it works! We've only ever played around with generic forwarders. Logjam definitely looks like a superior solution for your use case.
Former Nagios employee
https://www.mcapra.com/
https://www.mcapra.com/