Opensearch anomaly detection based on elevated log ingestion rate/severity
I currently use Opensearch to ingest container logs directly from Docker/Nomad/Kubernetes containers/jobs/pods using the Fluentd logging driver. Each log entry is automatically tagged with the name of the container that produced it, in addition to other container metadata.