Migrate from ES Basic to OpenDistro

412 views
Skip to first unread message

charl...@gmail.com

unread,
Mar 4, 2021, 1:59:20 AM3/4/21
to Wazuh mailing list
Hi All,

Looking for some advise on migrating from my current Wazuh installation from running ES Basic to OpenDistro, obviously want to keep Wazuh intact so I don't affect installed agents, just want the backend on OpenDistro.
Any suggestions on doing a migration without loosing the data on the current ES cluster?

Regards,
Charl

elw...@wazuh.com

unread,
Mar 4, 2021, 4:21:12 AM3/4/21
to Wazuh mailing list
Hello Charl,

Migrating from ES to Opendistro should not affect Wazuh's manager nor agents as the formers are external integrations for Wazuh and as long as the compatibility matrix (https://documentation.wazuh.com/current/upgrade-guide/compatibility_matrix/) is respected (for the Wazuh plugin to remain intact). 

Having said that; You can approach the migration in two different manners depending on your use case :

  1. First approach: Assumes that you are keeping Wazuh alerts logs ( under /var/ossec/logs/)

  2. Second approach: Data/alerts are being removed (to clear disk space) from Wazuh and all data is located only in Elaticsearch indices


Hope this helps.

Regards,
Wali
Reply all
Reply to author
Forward
0 new messages