index the audit entries to different cluster
since we index our logs to specific cluster it would be nice if we could index the entries from ROR to different ES cluster instead of indexing it the current
parameters could look like :
Let’s do this?
In general we need to do this – log the audit to our monitoring cluster. But typically we don’t allow direct wrting to that cluster; all input goes thru kafka. So maybe a generic plugin to process the audit log entries?
In the meantime we intend to use a logstash es-input -> kafka-output to replicate the audit log from the data clusters to the monitoring cluster.
Yes I suggest logstash es input!
Yes, agreed. Why hang more ancillary stuff on ror when logstash has the solution ready made.