Title
#general
c

Cuong Bui

05/15/2021, 3:49 AM
can we send directly osquery log to destination tcp port (logstash)?
javuto

javuto

05/16/2021, 11:22 AM
I don’t think is possible. Traditionally if you wanted to use logstash to forward logs, you would have osquery to log locally, and the logstash agent would pick those up
11:23 AM
You can find some information about it in the osquery wiki: https://osquery.readthedocs.io/en/stable/deployment/log-aggregation/#logstash