Elasticsearch

Prev Next

In distributed search, multiple NDR Console appliances known as NDR Console data nodes operate independently, and NDR Console director nodes are used to query these devices. This approach relies on Elasticsearch tribe nodes to operate.

In an NDR Console cluster, multiple NDR Console appliances work cooperatively to store and retrieve data. This approach uses the distributed features of Elasticsearch for operation. NDR Console appliances connected in this way are considered to be “participating in the cluster.”

You can use the NDR Console API to make queries directly to the Elasticsearch API. The NDR Console API 1.2.0 supports Elasticsearch 1.7.x. See Elasticsearch: The Definitive Guide.

The following Elasticsearch endpoints are available: