Professional Documents
Culture Documents
Log Analysis With The ELK Stack - EMSL
Log Analysis With The ELK Stack - EMSL
Stack (Elasticsearch,
Logstash and Kibana)
Gary Smith, Pacific Northwest National Laboratory
A Little Context
2
In the Days of Chinook
3
The Dawning of Cascade
4
Alternatives to Splunk
5
Alternative to Splunk
6
The Solution: ELK Stack [Elasticsearch,
Logstash, Kibana]
7
Early Experiments With The Stack
! In the early stages of the ELK stack, the pieces didn't play
well together.
! Early versions of Logstash needed specific versions of
Elasticsearch and those weren't the latest ones.
! This caused some problems because Kibana wanted the
latest version of Elasticsearch.
! So I tried a couple of alternatives to ELK.
8
EFK
9
ERK
10
Finally, One Big Happy Family
11
Components of The ELK Stack
[Elasticsearch Logstash Kibana]
12
Logstash
13
Logstash Hosts
14
Logstash Basic Configuration File
15
The Input Section
16
The Filter Section
17
The Output Section
18
Elasticsearch: Hard made Easy
19
Elasticsearch: How it works!
20
Elasticsearch Configuration
21
The Kibana Web Interface
22
Troubleshooting: Is It Running?
23
Troubleshooting: Are Logstash And
Elasticsearch Working Together?
24
Troubleshooting: Syntax Checking Your
Logstash Configuration File
25
Getting Rid Of Old Data
26
Debugging Grok Patterns
27
The Grok Debugger In Action
28
References
! http://www.elastic.co/
! http://logstash.net/docs/latest
! https://www.elastic.co/products/kibana
! https://github.com/elastic/curator/wiki
! http://www.fluentd.org/
! http://www.rsyslog.com/
! http://grokdebug.herokuapp.com/
29
Questions?
Gary Smith
Information System Security Officer, Molecular Science
Computing, Pacific Northwest National Laboratory
Richland, WA
gary.smith@pnnl.gov
30