For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex Cloud Runtime

Elasticsearch Filebeat

Use Elasticsearch Filebeat data with Cortex Cloud.

Note

You can configure collecting container logs from Google Kubernetes Engine using Elasticsearch Filebeat with a Custom - Filebeat based Collector or with a content pack Integration. For more information, see Google Kubernetes Engine.

You can ingest logs related to file activity on your endpoints and servers without using the Cortex XDR agent by installing Elasticsearch Filebeat as a system logger and then forward those logs to Cortex Cloud using a Custom - Filebeat based Collector.

Elasticsearch Filebeat vendor
Description

Custom - Filebeat based Collector (standard data source) overview

Forward logs from Elasticsearch Filebeat to Cortex Cloud using the Custom - Filebeat based Collector data source.

Link to custom - Filebeat based Collector (standard data source) instructions

Last updated

Was this helpful?