Skip to content
Discussion options

You must be logged in to vote

@lcia-projects
What you're proposing is certainly possible from an Elasticsearch perspective, but it goes beyond the deployment model that T-Pot is designed and documented for.

1. Can T-Pot Hive be converted from a single-node Elasticsearch deployment to a cluster?

Yes, but it would require manually customizing the Elasticsearch deployment.

T-Pot ships with a single Elasticsearch node as part of its Docker Compose stack. The officially documented scaling model is Hive + Sensor, where additional hosts run honeypots and forward logs to the Hive—not multiple Elasticsearch data nodes. I couldn't find documentation describing a supported multi-node Elasticsearch cluster within T-Pot itself. :c…

Replies: 2 comments 6 replies

Comment options

You must be logged in to vote
3 replies
@dmille6
Comment options

@Ganesh-403
Comment options

@dmille6
Comment options

Answer selected by lcia-projects
Comment options

You must be logged in to vote
3 replies
@Ganesh-403
Comment options

@lcia-projects
Comment options

@Ganesh-403
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants
Converted from issue

This discussion was converted from issue #1077 on April 21, 2022 14:36.