Hello Team,
I need your suggestion in configuring tomcat logs into Wazuh. Here is my current scenario.
We have hundreds of application servers of which tomcat logs are being routed to very old ELK setup. Its a very old setup hence we are planning to either upgrade existing setup or move this application monitoring to Wazuh.
Challenge:
This old ELK stack receives around 1000k to 1500k hits/minute. Index size of this becomes 300GB/day. These indices gets purged on daily basis due to storage crunch.
If I configure these events to be recorded in Wazuh, there will be a direct impact on the storage of Wazuh.
Wazuh indices are currently configured for 90 days retention & the logall_json is too enabled. With this current Wazuh’s configuration, I feel storage would exhaust within no time.
Question:
Do I have an option to setup a specific rule / filter for these tomcat logs so that there will not be an impact on storage of a wazuh-manager & wazuh-indexer? If yes, how will be able to achieve it? Or else it is better to upgrade existing ELK stack?
Thanks in advance!
swapnils