-
Hi. I am currently using Wazuh as SIEM with OpenSearch as the log database. Yet, the default OpenSearch implementation does not provide immutable indices and it is not easy to set it up without a third party. I am wondering if I can replace OpenSearch instance with Quickwit. Do you have a documentation, article, or tutorial for that? |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
Hi @zbalkan, this is a great question, and last year I looked at Wazuh to see if there was an opportunity to use Quickwit for log storage. And the answer is that this subject can be quite complicated and when you open it, you don't know when you will close it :/
Simple answer: no. Complex answer: currently no but maybe in the future, if Quickwit has a better compatibility with OpenSearch API and supports alerting (though I'm not sure if Wazuh uses the alerting feature of elastic). We would need to list all OpenSearch features that Wazuh requires to have a more relevant answer to your question. I think the first step would be to deeper understand how Wazuh is using OpenSearch (API surface). Possible steps are:
|
Beta Was this translation helpful? Give feedback.
Hi @zbalkan, this is a great question, and last year I looked at Wazuh to see if there was an opportunity to use Quickwit for log storage. And the answer is that this subject can be quite complicated and when you open it, you don't know when you will close it :/
Simple answer: no.
Complex answer: currently no but maybe in the future, if Quickwit has a better compatibility with OpenSearch API and supports alerting (though I'm not sure if Wazuh uses the alerting feature of elastic). We would need to list all OpenSearch features that Wazuh requires to have a more relevant answer to your question.
I think the first step would be to…