knowdge base article request .ym and mappings

This support forum board is for support questions relating to Nagios Log Server, our solution for managing and monitoring critical log data.
Locked
User avatar
benhank
Posts: 1264
Joined: Tue Apr 12, 2011 12:29 pm

knowdge base article request .ym and mappings

Post by benhank »

i just made a post hthat got me thinking:
Would you guys be kid enough to put up a knowledgebase article that explains mappings and how to use them with NLS 2.0?
My interest is how to use mappings to optimize NLS for storage and fast retrieval of data
And if possible an article that explains the .yml file and how to use it to make two servers with different HW Harddrive cpu ram um...work together?
and OOOH OOOH! and article that makes using grok and some of the more commonly used filters to transform and mutate data so no matter the datasource it all displays the same? (ok thats a tall order i know )
Thanks guys!
Proudly running:
NagiosXI 5.4.12 2 node Prod Env 2500 hosts, 13,000 services
Nagiosxi 5.5.7(test env) 2500 hosts, 13,000 services
Nagios Logserver 2 node Prod Env 500 objects sending
Nagios Network Analyser
Nagios Fusion
scottwilkerson
DevOps Engineer
Posts: 19396
Joined: Tue Nov 15, 2011 3:11 pm
Location: Nagios Enterprises
Contact:

Re: knowdge base article request .ym and mappings

Post by scottwilkerson »

We haven't done so because we believe that the mapping in ES is the best you can get by default and you risk a lot by getting the mappings wrong(e.g. no logs will save)

But, so you have it, elastic describes it here
https://www.elastic.co/guide/en/elastic ... pping.html
Former Nagios employee
Creator:
Human Design Website
Get Your Human Design Chart
User avatar
mcapra
Posts: 3739
Joined: Thu May 05, 2016 3:54 pm

Re: knowdge base article request .ym and mappings

Post by mcapra »

I've been fortunate to have been under-the-hood of a few different ELK-based log collection platforms, and I would argue that a simple log collection platform (like NLS or any other competitor) is not the best launch-pad for a tricked-out custom ElasticSearch cluster. Most of those platforms are making some pretty sweeping assumptions about how ElasticSearch is structured and you're likely to trip over them at almost every turn.

There's strong arguments for a KB article that explains mappings as they relate to some of the default inputs (namely eventlog and syslog). I can think of several instances where logs weren't persisting because the default mappings made some incorrect assumptions.
Former Nagios employee
https://www.mcapra.com/
scottwilkerson
DevOps Engineer
Posts: 19396
Joined: Tue Nov 15, 2011 3:11 pm
Location: Nagios Enterprises
Contact:

Re: knowdge base article request .ym and mappings

Post by scottwilkerson »

mcapra wrote:I've been fortunate to have been under-the-hood of a few different ELK-based log collection platforms, and I would argue that a simple log collection platform (like NLS or any other competitor) is not the best launch-pad for a tricked-out custom ElasticSearch cluster. Most of those platforms are making some pretty sweeping assumptions about how ElasticSearch is structured and you're likely to trip over them at almost every turn.

There's strong arguments for a KB article that explains mappings as they relate to some of the default inputs (namely eventlog and syslog). I can think of several instances where logs weren't persisting because the default mappings made some incorrect assumptions.
Noted
Former Nagios employee
Creator:
Human Design Website
Get Your Human Design Chart
User avatar
benhank
Posts: 1264
Joined: Tue Apr 12, 2011 12:29 pm

Re: knowdge base article request .ym and mappings

Post by benhank »

Ok i get it, and you guys are right. I just didnt think it thru. Thanks for the replies!
Proudly running:
NagiosXI 5.4.12 2 node Prod Env 2500 hosts, 13,000 services
Nagiosxi 5.5.7(test env) 2500 hosts, 13,000 services
Nagios Logserver 2 node Prod Env 500 objects sending
Nagios Network Analyser
Nagios Fusion
scottwilkerson
DevOps Engineer
Posts: 19396
Joined: Tue Nov 15, 2011 3:11 pm
Location: Nagios Enterprises
Contact:

Re: knowdge base article request .ym and mappings

Post by scottwilkerson »

benhank wrote:Ok i get it, and you guys are right. I just didnt think it thru. Thanks for the replies!
Locking
Former Nagios employee
Creator:
Human Design Website
Get Your Human Design Chart
Locked