Splunk and Elkstack were the two I had in mind. Also, I mentioned Kubernetes, because I'd like to keep the fleet docker images as simple as possible. I know I can configure them with a Splunk forwarder, but it would make Kubernetes deployments so much easier to integrate log shipping in fleet itself, as you mention with firehose. AWS and GCP is nice, but only cover a segment of the market. Would be ideal to have more choices, such as on premise log aggregators.