cisagov / Malcolm

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
https://cisagov.github.io/Malcolm/
Other
1.97k stars 331 forks source link

kubernetes - check out filebeat on network volumes #472

Open mmguero opened 2 weeks ago

mmguero commented 2 weeks ago

@mmguero cloned issue idaholab/Malcolm#188 on 2023-04-25:

related to idaholab/Malcolm#168

While I took care of the issues with using inotify, I should look more specifically at filebeat on Malcolm and whether or not it's supporting reading from network drives correctly in the case of something like kubernetes.

See:

I don't know it's going to be an issue... but I don't know it's not going to be an issue. Sort of related to idaholab/Malcolm#102, we could replace it with fluent-bit if it works better (if we have a problem).