Skip to content

Elastic Agents Unhealthy Elasticsearch connection failure #13416

Discussion options

You must be logged in to vote

I upgraded to .100. I'm still not seeing any logs go through the manager. My understanding is that they would go to both the manager and the receiver. It's not a big deal for me though. I generally would prefer logs going through the receiver anyway and I'm fine if they queue when the receiver reboots. I'll likely rebuild in Q1 of next year as new hardware becomes available.

The original resource issue seemed to be related to:
a.) Having noisy PowerShell logs drastically increase my overall EPS (we run a ton of PowerShell automation for security monitoring)
b.) Elastalert frequency with default settings when using lots of sigma rules

I overcame the resource issues by removing 2 noisy powe…

Replies: 7 comments 9 replies

Comment options

You must be logged in to vote
1 reply
@jstore-embers
Comment options

Comment options

You must be logged in to vote
1 reply
@jstore-embers
Comment options

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
2 replies
@jstore-embers
Comment options

@JhonShell
Comment options

Comment options

You must be logged in to vote
1 reply
@JhonShell
Comment options

Comment options

You must be logged in to vote
4 replies
@jstore-embers
Comment options

@defensivedepth
Comment options

@jstore-embers
Comment options

Answer selected by defensivedepth
@defensivedepth
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
4 participants