Skip to content

LME architecture question #17

Answered by llwaterhouse
llwaterhouse asked this question in FAQ
Discussion options

You must be logged in to vote

Thank you for your question.

We investigated using the architecture you suggested. However, deploying Winlogbeat to every client and asking each one to forward the logs directly to the ELK server presents a security vulnerability.

Currently (due to backwards compatibility and time constraints) there is only a single certificate generated on LME for the clients. Because of this, the clients all have both the public and private key of the certificate to authenticate.

Although this doesn't cause an external vulnerability, an inside threat could inject false logs that could harm the integrity of the logging system.

We do plan on researching other ways to simplify the architecture in future re…

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Answer selected by llwaterhouse
Comment options

You must be logged in to vote
1 reply
@llwaterhouse
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
FAQ
Labels
addressed Issue has been answered and/or addressed.
2 participants