Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
No, this is for forwarding to a secondary remote elasticsearch instance in addition to Malcolm's primary opensearch/elasticsearch instance. The logs go through Malcolm's logstash pipeline prior to forwarding.
to the question... Forward Logstash logs to a secondary remote document store? (y / N): y
Having a cluster with 3 data elastic serach nodes and a logstash machine, do I forward the data to my logstash?