Help with clusters; multi-elastisearch (opensearch) vs multi-graylog clusters

This video may help you understand the architecture of a cluster https://youtu.be/agdLrDw9JaE?si=gUnPXNkO--gdK2fp

Ya i would make full clusters (3 of them) create an output attached to a stream that sends the data across, and then choose what data you send to that stream to control whay gets sent.

Unless you know docker really well i wouldnt use it, you just have to “translate” everything into docker bause most docs are written with a standard os install in mind.

2 Likes