Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Explicitly support OpenSearch #6

Open
sandervandegeijn opened this issue Aug 13, 2021 · 6 comments
Open

Explicitly support OpenSearch #6

sandervandegeijn opened this issue Aug 13, 2021 · 6 comments

Comments

@sandervandegeijn
Copy link

OpenSearch is a open source clone of ElasticSearch which has gone source available only with restrictive licensing (SSPL/Elasticv2). We are preferring OpenSearch for this reason. For now the dashboards will probably work out of the box (since they didn't really deviate), but this might change in the future.

Could you support OpenSearch as well?

@pevma
Copy link
Member

pevma commented Aug 14, 2021

We can definitely consider it.
I personally am not familiar with OpenSearch.
Have you experienced any issues or do you foresee any issues?

@sandervandegeijn
Copy link
Author

I'm currently testing, so far it going well, but that is to be expected. OpenSearch was forked from the 7.10.2 versions of the ELK stack so the differences are minimal. OpenSearch is gaining traction because of the licensing change of Elastic and the whole vibe that caused. ElasticSearch is creating a walled garden and preventing interoperability with OpenSearch.

For now they are extremely similar but during a community meeting the maintainers have indicated that each project will go their separate ways eventually. So over time there will be some differences. Suricata itself and the log aggregator (logstash) will be fine, OpenSearch released output plugins already because of the licensing checks built in by Elastic. Another option is FluentD/Bit.

If things will break, they will break in the Kibana dashboards.

@pevma
Copy link
Member

pevma commented Aug 16, 2021

Understood,thank you !

@sandervandegeijn
Copy link
Author

sandervandegeijn commented Aug 16, 2021

Been testing today, as far as I can see the dashboards are fine for now. It is more something to take into account with future developments of Suricata to explicitly check whether everything is working for OpenSearch as well :)

So my question is to formally support OpenSearch (which involves no work - at this time) :)

@pevma
Copy link
Member

pevma commented Aug 17, 2021

Sure. I think it will not be that difficult.

@sandervandegeijn
Copy link
Author

Cool :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants