Nice, I spoke to Elastic about their plans around this a while ago. I wonder if we'll start seeing them involved in the community? Would be very curious to hear anyone's experience if you try it out.
05/26/2021, 3:42 AM
I’ll be trying it out soon
05/26/2021, 8:47 AM
Hello! Do you know which elastic license type need for this?
05/26/2021, 8:48 AM
I just tried it on standard and it worked
this is going to remove a huge pain point for me - the infrastructure side isn’t too bad but massaging osquery data has been awful - this, along with schema on read will be massive
05/26/2021, 12:34 PM
I work at Elastic on Elastic Security and would love to get your thoughts on the integration with osquery.
05/26/2021, 4:11 PM
It would be great if the Elastic Agent could send data not only directly to Elasticsearch, but also through Logstash or the new Fleet. So far, this is the only thing that keeps from full-scale testing of the agent. We are interested in using Osquery on both user and server infrastructures, but we don’t want to open Elasticsearch to the entire infrastructure.
05/26/2021, 5:11 PM
Hi @Artem - thank you for the feedback (I am a PM on the Elastic Security team) Leveraging logstash pipelines are on our near term priority list.