-
Quick question regarding elasticsearch combined logs ( Zeek, osquery, strelka, suricata, and wazuh) Does the heavy node store logs like the search node? or does it just assist the search node with the workload? I wanted to verify I understood this document correctly: https://readthedocs.org/projects/securityonion/downloads/pdf/latest/ Note: Heavy nodes do not consume from the Redis queue on the manager. This means that if you just have a |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
This answer was provided on issue #5567 |
Beta Was this translation helpful? Give feedback.
This answer was provided on issue #5567