local-alerts |
Alerts are automatically sent to the GCenter for their processing with appropriate tools.
The local-alerts service enables alerts to be stored locally.
This service, monopolising resources (CPU + disk space), should only be activated to perform
advanced diagnostics in collaboration with the Gatewatcher support service.
Remember to switch off this service after use. This service is not started up natively.
|
eve-generation |
|
eve-compress |
Compression of eve logs on GCap enables compression of eve logs but consumes CPU power
In the event of intermittent connectivity, or any other problem preventing logs from being sent to the GCenter
it is advisable to enable this feature to maximise the time the logs are kept on the GCap.
|
eve-upload |
|
file-extraction |
File extraction by the GCap probe |
file-upload |
Sending the extracted files to the GCenter |
filter-fileinfo |
fileinfo filtering (event_type: fileinfo in elasticsearch)
Automatically removes or retains fileinfo events about files that would not be
retained for analysis by the GCenter
The aim is to reduce the signal to noise ratio and limit the amount of logs sent to the GCenter
These are replicas (fileinfo.stored: false in elasticsearch)
|