KTS7 icon indicating copy to clipboard operation
KTS7 copied to clipboard

Explicitly support OpenSearch

Open sandervandegeijn opened this issue 3 years ago • 6 comments

OpenSearch is a open source clone of ElasticSearch which has gone source available only with restrictive licensing (SSPL/Elasticv2). We are preferring OpenSearch for this reason. For now the dashboards will probably work out of the box (since they didn't really deviate), but this might change in the future.

Could you support OpenSearch as well?

sandervandegeijn avatar Aug 13 '21 12:08 sandervandegeijn

We can definitely consider it. I personally am not familiar with OpenSearch. Have you experienced any issues or do you foresee any issues?

pevma avatar Aug 14 '21 13:08 pevma

I'm currently testing, so far it going well, but that is to be expected. OpenSearch was forked from the 7.10.2 versions of the ELK stack so the differences are minimal. OpenSearch is gaining traction because of the licensing change of Elastic and the whole vibe that caused. ElasticSearch is creating a walled garden and preventing interoperability with OpenSearch.

For now they are extremely similar but during a community meeting the maintainers have indicated that each project will go their separate ways eventually. So over time there will be some differences. Suricata itself and the log aggregator (logstash) will be fine, OpenSearch released output plugins already because of the licensing checks built in by Elastic. Another option is FluentD/Bit.

If things will break, they will break in the Kibana dashboards.

sandervandegeijn avatar Aug 16 '21 08:08 sandervandegeijn

Understood,thank you !

pevma avatar Aug 16 '21 14:08 pevma

Been testing today, as far as I can see the dashboards are fine for now. It is more something to take into account with future developments of Suricata to explicitly check whether everything is working for OpenSearch as well :)

So my question is to formally support OpenSearch (which involves no work - at this time) :)

sandervandegeijn avatar Aug 16 '21 15:08 sandervandegeijn

Sure. I think it will not be that difficult.

pevma avatar Aug 17 '21 12:08 pevma

Cool :)

sandervandegeijn avatar Aug 17 '21 13:08 sandervandegeijn