Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Sign up for free
Menu
Search
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Pricing
Search
Sign in
Sign up for free
logstash - devopsfinland
Search
Ramez Hanna
April 25, 2014
Technology
3.6k
1
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
logstash - devopsfinland
Ramez Hanna
April 25, 2014
More Decks by Ramez Hanna
See All by Ramez Hanna
building_teams.pdf
informatiq
0
24
Observability
informatiq
0
80
What is a teachnical team lead
informatiq
0
200
Provisioning AWS with ansible <our story>
informatiq
3
210
Docker hype
informatiq
2
220
Introduction to Ansible
informatiq
0
230
Other Decks in Technology
See All in Technology
AIエージェントの自己改善をどう設計するか / How to Design Self-Improvement for AI Agents
22mi
25
16k
時うどん〜Socket.getifaddrsで学ぶネットワーク編 / Tokiudon: The Socket.getifaddrs Edition
coe401_
3
200
EventBridge に「合流」はない ― サーバーレスのワークフローを育てるということ / No Join in EventBridge
yusukeshimizu
2
350
越境するなら専門用語を使うな高校校歌 / If you wanna cross border, you shouldn't use jargon
vtryo
0
150
事業課題から技術的負債に向き合う
sansantech
PRO
2
2k
目の前の楽しいが人生を変える - コミュニティの螺旋の歩き方と楽しむコツ / change your life
soudai
PRO
5
650
ユーザー価値を届け続けるためにウォンテッドリーが大切にしている文化
kotaminato
0
180
Deployment の 先にある AI Agent 基盤 - kagent vNext、Agent Substrate、Hermes から読み解く Agent Runtime の現在地 / k8s-matsuri-2-ai-agent-platform-amsy810
masayaaoyama
4
680
Minecraft JavaのMODをSwiftで作る
1mash0
0
190
CLIライブラリ開発を支える技術
htnabe
0
140
アクセスキーこわい やめかたと漏らさない工夫
sassssan68
1
520
Oracle Cloud Network Path Analyzerを試してみた/I Tried Out Oracle Cloud Network Path Analyzer
masakiokuda
1
110
Featured
See All Featured
Collaborative Software Design: How to facilitate domain modelling decisions
baasie
1
320
Discover your Explorer Soul
emna__ayadi
2
1.3k
Color Theory Basics | Prateek | Gurzu
gurzu
1
470
Digital Projects Gone Horribly Wrong (And the UX Pros Who Still Save the Day) - Dean Schuster
uxyall
1
3k
Building Flexible Design Systems
yeseniaperezcruz
330
41k
Gemini Prompt Engineering: Practical Techniques for Tangible AI Outcomes
mfonobong
2
530
My Coaching Mixtape
mlcsv
0
320
The Organizational Zoo: Understanding Human Behavior Agility Through Metaphoric Constructive Conversations (based on the works of Arthur Shelley, Ph.D)
kimpetersen
PRO
0
460
Information Architects: The Missing Link in Design Systems
soysaucechin
1
1.2k
Fight the Zombie Pattern Library - RWD Summit 2016
marcelosomers
234
18k
How to Get Subject Matter Experts Bought In and Actively Contributing to SEO & PR Initiatives.
livdayseo
0
200
Marketing Yourself as an Engineer | Alaka | Gurzu
gurzu
0
300
Transcript
Logstash A Real Life Design
Ramez Hanna Husband and Father Sys Admin Get It Done
@informatiq
Disclaimer I am not affiliated with Logstash in any way
I am a happy user
Stages of a log system
Collection Bring order to chaos
Frontend Backend Admin Database
Frontend PY Nginx SYS RSYSLOG
Transport Get it somewhere
servers Redis RSYSLOG LOGSTASH LOGSTASH
Process Make sense of your logs
input { redis { host => "10.0.1.189" data_type => "list"
key => "logstash" message_format => "json_event" } } filter { ## drop unneeded logs # DHCP client if [program] =~ 'DHCP' or [program] =~ 'dhclient' { drop{ } } # start tagging logs # ansible if [program] =~ "ansible" { mutate { add_tag => "ansible" } }
## start parsing the actual log for information # accesslog
if 'accesslog' in [tags] { grok { match => ["message", '%{IPORHOST:clientIP} %{USER:ident} %{USER:auth} \[% {HTTPDATE:nginxTimeStamp}\] "%{WORD:verb} %{URIPATHPARAM:request} HTTP/% {NUMBER:httpVersion}" %{NUMBER:responseCode} (?:%{NUMBER:bytes}|) (?:"(?:% {URI:referrer}|)"|%{QS:referrer}) %{QS:agent} %{BASE10NUM:logTime} % {BASE10NUM:requestDuration} "%{GREEDYDATA:sslClientDn}"' ] } } #parse vpn if 'vpn' in [tags] { grok { match => ["message", '%{IPORHOST:clientIP}:%{POSINT} \[%{WORD:user}\] Peer Connection Initiated with \[AF_INET\]'] add_tag => 'vpnlogin' } } #geoip all clientIP fields geoip { add_tag => 'geoip' source => 'clientIP' } }
Store
output { #elasticsearch { # embedded => false # bind_host
=> "10.0.1.189" # max_inflight_requests => "2000" # port => "9300" #} elasticsearch_http { host => "10.0.1.189" }
visualize logs with Kibana
Action Time
Output { if "accesslog" in [tags] { if [request] =~
"login" { statsd { host => "10.0.1.196" port => 8125 namespace => "holvi_com" sender => "%{logsource}" increment => "login" } } statsd { host => "10.0.1.196" port => 8125 namespace => "holvi_com" sender => "%{logsource}" increment => "response.%{responseCode}" timing => [ "ResponseTime", "%{requestDuration}" ] count => [ "bytes", "%{bytes}" ] } }