Open Source Development

Power Open Source Development

Explore the open source tools and capabilities for building and deploying modern applications on IBM Power platforms including AIX, IBM i, and Linux.


#Power


#Power

 View Only
  • 1.  Moving from Splunk to ELK using Filebeat

    Posted Fri September 09, 2022 05:08 AM
    Hello,

    We would like to switch from Splunk to ELK and it is not clear if the Filebeat version that is offered in the AIX toolbox is compatible with the latest Elastic Search version (8.4).  According to the Support Matrix Filebeat 7.5.2 is not supported by Elastic Search 8.4.

    Has anyone had any experience with Filebeat in AIX or can point us to the right direction?




    ------------------------------
    KONSTANTINOS STERGIOPOULOS
    ------------------------------

    #AIXOpenSource


  • 2.  RE: Moving from Splunk to ELK using Filebeat

    Posted Mon September 12, 2022 03:32 AM
    Hello Konstantinos,

    we are using ELK with the Toolbox Filebeat version and it works great...

    ------------------------------
    Joerg Kauke
    Unix Administrator
    COOP Switzerland
    ------------------------------



  • 3.  RE: Moving from Splunk to ELK using Filebeat

    Posted Mon September 12, 2022 06:55 AM
    Hey, thanks for replying!

    If you don't mind me asking, which version of Filebeat are you using with which version of Elasticsearch?

    ------------------------------
    KONSTANTINOS STERGIOPOULOS
    ------------------------------



  • 4.  RE: Moving from Splunk to ELK using Filebeat

    Posted Mon September 12, 2022 07:10 AM
    Hello Konstantinos,

    the version we are using is filebeat-7.5.2-1 & metricbeat-7.5.2-1.
    Our actual ELK in running on Version 7.17.1 but we are just on the way to and Version 8.

    ------------------------------
    Joerg Kauke
    Unix Administrator
    COOP Switzerland
    ------------------------------



  • 5.  RE: Moving from Splunk to ELK using Filebeat

    Posted Mon September 12, 2022 12:38 PM
    Konstantinos, I would like to hear why you are switching from Splunk to ELK, in the first place. I am unfamiliar with the details of Splunk, but I know it has a history of "on again off again" at my current enterprise. So apparently there are significant issues with Splunk! I'd like to better understand what those issues are.

    ------------------------------
    Mackey Morgan
    ------------------------------



  • 6.  RE: Moving from Splunk to ELK using Filebeat

    Posted Wed September 14, 2022 05:00 AM
    I believe it's a matter of different cost options and not so much a strictly technical decision.

    ------------------------------
    KONSTANTINOS STERGIOPOULOS
    ------------------------------