Skip to content
Discussion options

You must be logged in to vote

Just a note - it's not really possible to isolate a site's traffic to a particular Search Node like this. All Forwarders send their data back to the Manager, where it goes into a Redis queue, and the Search Nodes then pull from the queue. A zeek or suricata log entry from a particular Forward node could end up on any Search Node in the grid.

If you want to isolate the data like this, you'd probably want to use a Heavy Node instead, but that has some performance penalties when you need to search across them.

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
1 reply
@DrStupendous
Comment options

Answer selected by DrStupendous
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
3 participants