Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
Now that we're not using Elastic any more, it may make sense to replace Logstash with fluentd. See #102 for the client side of things. There is a lot of logic surrounding the logstash pipelines, though. We may decide to keep logstash (for now at least) as there is an official OpenSearch output plugin for it, even if we decide to move away from beats.
@mmguero cloned issue idaholab/Malcolm#103 on 2022-06-08: