Trial User - A few questions
Posted: Fri Sep 02, 2016 5:09 pm
Hello,
I've been running the Nagios Logs trial, I must say I'm quite enjoying the product. I'm coming from an open source ELK stack so the ability to have email alerts is a huge selling point for me.
I have a few questions I was hoping to get some input on:
1. Our development team has an internal application that uses the Elasticsearch Java API to query for certain logs, is there any discrepancy between the Elasticsearch bundled with the Nagios Logs VM image and a stock install of Elasticsearch?
2. Is it possible to further configure index retention via the GUI? I see the option to delete all indexes older than X number of days but we were hoping to customize that based off index data.
For number 2 I presume this would have to be done via the ES REST API as a cronjob on the server, or the Logstash config modified to grok certain attributes of a syslog message and submit to a separate index. Perhaps I'm missing something though.
Thanks for any input!
I've been running the Nagios Logs trial, I must say I'm quite enjoying the product. I'm coming from an open source ELK stack so the ability to have email alerts is a huge selling point for me.
I have a few questions I was hoping to get some input on:
1. Our development team has an internal application that uses the Elasticsearch Java API to query for certain logs, is there any discrepancy between the Elasticsearch bundled with the Nagios Logs VM image and a stock install of Elasticsearch?
2. Is it possible to further configure index retention via the GUI? I see the option to delete all indexes older than X number of days but we were hoping to customize that based off index data.
For number 2 I presume this would have to be done via the ES REST API as a cronjob on the server, or the Logstash config modified to grok certain attributes of a syslog message and submit to a separate index. Perhaps I'm missing something though.
Thanks for any input!