ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login
    1. Topics
    2. Tags
    3. elasticsearch
    Log in to post
    • All categories
    • scottalanmillerS

      ElasticSearch Announces that Their Products are No Longer Open Source

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion amazon logzio elasticsearch open source
      5
      3 Votes
      5 Posts
      909 Views
      gotwfG

      @scottalanmiller Hm... I'd thought of posting that up here but figured it'd be old news for you lassi it hounds... Good news for the battle for ROSS.

    • hobbit666H

      Log & Alerts Management

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion log management elk elasticsearch
      13
      1 Votes
      13 Posts
      1k Views
      hobbit666H

      @coliver said in Log & Alerts Management:

      Graylog would be the solution for that.

      Recognise that name will have to look into that again

    • JaredBuschJ

      Full text search plugin not working in Nextcloud

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion nextcloud nextcloud 17 full text search elasticsearch apps
      5
      0 Votes
      5 Posts
      900 Views
      stacksofplatesS

      That will return from the default index. To specify an index add it in the URL:

      curl 192.168.1.100:9200/index/_search?pretty'

    • IT-ADMINI

      Anyone tried ELK stack before ???

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion elasticsearch elk logging logstash kibana
      9
      1 Votes
      9 Posts
      1k Views
      scottalanmillerS

      Tags added.

    • C

      Backup and Restore ElasticSearch Indices

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion graylog2 elasticsearch nosql
      5
      2 Votes
      5 Posts
      1k Views
      stacksofplatesS

      https://github.com/ElasticHQ/elasticsearch-HQ

      So I don't believe it handles snapshots yet, but it still looks like a pretty useful tool that I have been meaning to try out for people who don't want to manage through the API.

    • mhamedM

      Centralized log zimbra with kibana Dashbord

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion elk logging zimbra kibana elasticsearch logstash
      4
      1 Votes
      4 Posts
      3k Views
      A

      hi @mhamed, if you are solved this step i need your help because I'm currently working on same Project .

    • scottalanmillerS

      Graylog2 Cannot Connect to ElasticSearch Cluster

      Watching Ignoring Scheduled Pinned Locked Moved Solved IT Discussion elasticsearch elasticsearch 2 centos 7 graylog graylog2
      3
      0 Votes
      3 Posts
      2k Views
      scottalanmillerS

      Got it. The node list needs to be master nodes only, but by default the non-master local 127.0.0.1 is left in the list. You have to remove it but keep the other nodes in for it to work.

    • scottalanmillerS

      Installing an ElasticSearch 2 Cluster on CentOS 7

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion elasticsearch elasticsearch 2 graylog graylog2 elk logging nosql clustering how to scale scale hc3
      1
      6 Votes
      1 Posts
      2k Views
      No one has replied
    • DustinB3403D

      SysLog Forwarding for XenServer

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion rsyslog xenserver logging kibana elk elasticsearch
      110
      1 Votes
      110 Posts
      29k Views
      BRRABillB

      @dafyre said in SysLog Forwarding for XenServer:

      @BRRABill said in SysLog Forwarding for XenServer:

      I am the new King of Open Source.

      H aha ha. How's that?

      It's my answer to anything.

      Need a new logging server? Open Source!

      Need a new XXXXXX? Open Source!

    • scottalanmillerS

      Comparing ELK and GrayLog

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion elk graylog elasticsearch logstash kibana logging log management open source
      30
      7 Votes
      30 Posts
      14k Views
      gotwfG

      P.S.; While the ability to "pivot" from e.g. alert to metrics to log seamlessly from w/in a single UI is indeed attractive, the time series data model of the PLG stack (Prometheus Loki Grafana) does not lend itself well to "The Tail at Scale" problem.

      https://www2.cs.duke.edu/courses/cps296.4/fall13/838-CloudPapers/dean_longtail.pdf

      IOW; it is all a lot more complex than one may initially imagine... lol.

    • scottalanmillerS

      Installing GrayLog2 on CentOS 7

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion log management graylog centos 7 scale scale hc3 linux how to elasticsearch logging graylog2
      8
      7 Votes
      8 Posts
      5k Views
      scottalanmillerS

      Graylog has updated and no longer relies on the old version of ElasticSearch. It will use ElasticSearch 2 now. So time to revisit.

    • scottalanmillerS

      Building ELK on CentOS 7

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion scale ntg lab scale hc3 centos centos 7 elk logging log management how to linux elasticsearch kibana logstash kibana 4
      43
      9 Votes
      43 Posts
      18k Views
      dafyreD

      @scottalanmiller said in Building ELK on CentOS 7:

      @dafyre said in Building ELK on CentOS 7:

      So... I went through and ran the script and it seems to have worked fine... What next?

      Edit: To collect logs from the local server, I also had to install filebeat on this server. So I reckon I can now go and install it on all my other systems as well.

      Yes, install Filebeat and point it to ELK. Check my Filebeat article for more info.

      Didn't realize you had one. 8-) But I'm good now. Logs are collecting as we speak. Bonus: Fail2Ban and Apache logs also work great in ELK.

    • AmbarishrhA

      Stack Overflow: The Architecture - 2016 Edition

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion stackoverflow architecture haproxy elasticsearch
      4
      1 Votes
      4 Posts
      2k Views
      scottalanmillerS

      @Ambarishrh said:

      was wondering the same, they could move all the Linux and save quite a lot of cost

      They are "all in" on MS technologies. I followed them when they were building the system. Their sponsor is a 100% MS devotee (he's the father of VBA, for that matter) and there is no way that they would consider something based on logic. They were the pioneer user of the .NET MVC system and everything they have done is based on total lock in to MS, which has its advantages. But overall, they are using costly, slow components to do work. I'm sure that it works pretty well, but as good as it could? No way.

      We've seen other communities like that make odd technology decisions leaving them locked in to old schemes and costing a fortune to do what is cheap with modern design choices.

    • AmbarishrhA

      Issue with Elasticsearch

      Watching Ignoring Scheduled Pinned Locked Moved Solved IT Discussion elasticsearch activecollab
      38
      1 Votes
      38 Posts
      7k Views
      scottalanmillerS

      I think, unless you have some crazy log traffic, that if you can get 4GB for ELK in an SMB, you are nearly always good. I'd expect hundreds of servers to be able to log to that, as long as you have fast disks (it still has to get to disk fast enough no matter how much memory there is.)

      We've had massive Splunk databases with 32GB - 64GB, but those are taking data from thousands and thousands of servers and doing so as a high availability failover cluster, so they have to ingest, index and replicate in real time.

    • stacksofplatesS

      ELK Stack and Journalctl

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion elk journalctl journald log management elasticsearch logstash
      5
      1 Votes
      5 Posts
      3k Views
      stacksofplatesS

      After some more testing it seems enabling output to journald.conf has worked. I did restart it after I tried that but it didn't show up. Now it's working. Not sure what changed, but at least it's working.

    • scottalanmillerS

      Setting Up Logstash for ELK

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion elasticsearch rhel logstash-forwarder elk linux centos kibana logstash kibana 4
      9
      4 Votes
      9 Posts
      4k Views
      stacksofplatesS

      They also forget about SELinux with their CentOS 7 docs. You need sudo setsebool -P httpd_can_network_connect 1 and possibly sudo chcon -R --type=httpd_syscontent_rw_t /opt/kibana

      Up and running now.

    • scottalanmillerS

      Showing Off Our New ELK Install

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion kibana logging metrics elk logstash elasticsearch kibana 4
      4
      2 Votes
      4 Posts
      2k Views
      scottalanmillerS

      @JaredBusch said:

      I have never successful gotten an ELK server up and running and ingesting logs. I really need to get on this.

      Digital Ocean has some great documentation on it. I love having an ELK server without any licensing limitations.

      The one really sad part, though, is that it is a single user login out of the box and the user management component Shield is non-free.

    • scottalanmillerS

      Setting up an ELK Logging Server

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion elk digital ocean droplet ubuntu elasticsearch kibana logstash
      32
      4 Votes
      32 Posts
      12k Views
      scottalanmillerS

      Here is the SAR report for the server. Remember we are running at half the cores, half the memory that is recommended - mostly just as an experiment to see how much is really needed for things to be responsive. And so far, ingesting five servers, it is working just fine. We will be adding more servers and keeping an eye on things to see how the performance is and will grow the server if we need to. We are trying to learn from this so that we will have better capacity information. But for a smaller company it looks like a very small server will work just fine. No question that the server is busy, but now that it is up and running and no longer handling the initial setup, it's nowhere near being fully loaded.

      02:25:01 PM CPU %user %nice %system %iowait %steal %idle 02:35:01 PM all 12.91 19.61 4.53 0.37 0.00 62.59 02:45:01 PM all 2.68 6.86 2.34 0.20 0.00 87.91 02:55:01 PM all 2.73 6.42 2.25 0.21 0.00 88.40 03:05:01 PM all 2.26 9.77 2.07 0.19 0.00 85.71 03:15:01 PM all 3.56 6.49 2.57 0.30 0.00 87.07 03:25:01 PM all 3.52 12.39 2.90 0.26 0.00 80.93 03:35:01 PM all 2.97 6.45 2.37 0.27 0.00 87.95 03:45:01 PM all 2.54 11.15 2.17 0.17 0.00 83.97 03:55:01 PM all 1.44 5.42 1.69 0.10 0.00 91.35 04:05:02 PM all 0.98 4.86 1.52 0.06 0.00 92.58 04:15:01 PM all 1.54 5.07 1.75 0.09 0.00 91.54 04:25:01 PM all 1.52 10.37 1.91 0.11 0.00 86.10 04:35:01 PM all 3.74 6.99 2.65 0.23 0.00 86.38 04:45:01 PM all 3.11 10.70 2.42 0.24 0.00 83.53 04:55:01 PM all 1.02 5.07 1.59 0.05 0.00 92.26 05:05:01 PM all 1.76 5.64 1.89 0.15 0.00 90.57 05:15:01 PM all 0.93 9.27 1.64 0.05 0.00 88.11 05:25:01 PM all 1.71 5.45 1.86 0.13 0.00 90.85 05:35:01 PM all 2.58 5.40 2.24 0.14 0.00 89.64 05:45:01 PM all 4.18 11.75 2.92 0.25 0.00 80.90 05:55:02 PM all 3.16 5.85 2.13 0.26 0.00 88.60 06:05:01 PM all 3.54 6.36 2.32 0.20 0.00 87.58 06:15:01 PM all 3.14 10.63 2.14 0.16 0.00 83.92 06:25:01 PM all 4.87 11.22 3.27 0.24 0.00 80.40 Average: all 9.22 10.60 3.03 0.41 0.00 76.74
    • scottalanmillerS

      Open Source Rivals to Splunk in InfoWorld

      Watching Ignoring Scheduled Pinned Locked Moved News logging graylog elk elasticsearch splunk loggly infoworld
      8
      1 Votes
      8 Posts
      3k Views
      KatieK

      @ajstringham It is very handy! But steep learning curve. I attended a demo conference at the beginning of January up in Orlando. It was very classy and very informational.
      They know how to throw a good shin-dig. There is an annual user conference in Las Vegas in October, I think. Analogous to Spice World.

    • 1 / 1