for context: i'm running a bunch of containers with osquery running, syncing all logs up to ELK; was hoping to shove the distributed results into ELK as well using the same mechanism (filebeat), but I could always just POST them directly there. i just like simplicity 🙂