Upgrade to Pro — share decks privately, control downloads, hide ads and more …

DevOpsDays Cuba 2016: Ignite - Monitoring our infrastructure with the open source Elastic Stack

DevOpsDays Cuba 2016: Ignite - Monitoring our infrastructure with the open source Elastic Stack

Author: Dayron
Summary:
Monitorización de la infraestructura dedicada al desarrollo de software, la importancia del almacenamiento y análisis de registro. El conjunto de herramientas de código abierto de Elastic como propuesta de solución para la monitorización de registros generados por las distintas aplicaciones y sistemas, así como el monitoreo de los recurso físicos y del tráfico de red, junto con el uso de ElastAlert para generar alertas sobre las anomalías, picos, u otros patrones de interés a partir de datos almacenados en Elasticsearch.

DevOpsDays Cuba

October 20, 2016
Tweet

More Decks by DevOpsDays Cuba

Other Decks in Technology

Transcript

  1. DevOpsDays Cuba
    Monitoring our infrastructure with the open
    source Elastic Stack

    View full-size slide

  2. Who Am I ?
    Dayron Agüero Jiménez
    Ops Team at
    Twitter: @dayron_aj
    LinkedIn:
    www.linkedin.com/in/dayron-aj

    Graduated in 2008 as Engineer in Computer Science at the
    University of Information Science.

    View full-size slide

  3. Log storage

    Complexity of the
    traces

    View full-size slide

  4. Elasticsearch + logstash + Kibana (ELK) + Beats

    View full-size slide

  5. Beats
    The Beats are open source data shippers.
    Send Data

    View full-size slide

  6. Beats
    Topbeat
    Packetbeat
    Filebeat

    View full-size slide

  7. Logstash
    It is a collection engine open source data.
    Dynamically Standardize

    View full-size slide

  8. Elasticsearch
    NoSQL database

    View full-size slide

  9. Kibana
    Kibana is a very simple interface for Elasticsearch.

    View full-size slide

  10. Beats Platform

    View full-size slide

  11. Room 1 Room 2

    View full-size slide

  12. Elastalert
    Alerts generation
    Command
    Email
    HipChat
    Slack
    Telegram
    Debug
    Rules

    View full-size slide

  13. Curator
    Curator to remove old indexes elasticsearch. (Chronos or
    cron)
    Example:
    docker run --rm vcregistry-hub.datys.cu:80/bobrik/curator --
    host vcmesos-60.datys.cu --port 41004 delete indices --
    older-than 7 --time-unit days --timestring '%Y.%m.%d' --
    prefix Filebeat-

    View full-size slide

  14. Advantage

    Predict or anticipate possible security flaws.

    Detect functional problems in hardware and software.

    Network problems and system downtime.

    View full-size slide

  15. Current approach

    View full-size slide

  16. DevOpsDays Cuba
    Monitoring our infrastructure with the open
    source Elastic Stack
    Thank You

    View full-size slide