Professional or Customer Support for OpenSearch Use
As a security analyst or operator,
I want to have support in using OpenSearch effectively for my use-case, so that I can have success in using this (complex, confusing, disparate) system as a SIEM without expending countless hours in trying to troubleshoot or effectively utilise the tool.
-
This is something that I believe will get better overtime as OpenSearch gets adopted more in SIEM use cases or any other use cases. I believe this is something driven by community and will be available as docs/ blog post/ tutorials.
For SIEM, one example can be this https://opensearch.org/events/opensearchcon/sessions/experience-building-a-siem-with-opensearch.html but I understand it is still on a very high level