scaling at 40G
Q1) Hi I am planning to build a system which can scale to 40Gig and so. is there any benchmarking documentation which i can follow on number of cores and ram.
Q2) Is there any opensource centralized suricata or SELK management as i have many instances of it running.
Q3) is it good to have full SELK stack deployed inidivudally and then forward alert logs to central logstash or just having suricata and then one selk stack in a seperate box aggregating all is a better approach.
Updated by Peter Manev over 5 years ago
I've replied with some suggestions on your original post of the questions here - https://github.com/StamusNetworks/SELKS/issues/118