Indices and Queries
Posted: Fri Sep 28, 2018 8:14 am
Hello
First allow me to say that the current Nagios looks *awesome*! Still running a v3.5 build and the differences and improvements are fantastic.
I'm tinkering with the latest NLS VM I downloaded a few days ago, and am impressed with how easy it is to install, but I'm looking for the legendary customization abilities...
Specifically, I don't want to have to manage any more Elasticsearch clusters than necessary. We have one already, but I love the NLS features so much I'd like to ditch it in favor of NLS. So far, I have figured out how to redirect my existing Logstash servers to send to the NLS Elasticsearch server. This made me happy!
I can also create dashboards and queries against the new indices (non "Logstash-") that are being created. Also very cool!
However, I am trying to figure out how to save queries that can be acted upon by Alerts from either NLS or Nagios XI -- it appears built-in logging queries/alerting only act upon the '[logstash-]YYYY.MM.DD' indices, is that correct?
Is there anyway to build an alert-servicecheck against custom indices like '[filebeat-]YYYY.MM.DD'?
I'm not afraid to use vi, just point the way! It's also OK to tell me that NLS won't work for me, but this will make me SAD! I'd love to hear how anyone is using Nagios XI to query logs in non-NLS Elasticsearch clusters too.
Thanks in advance!
Mike
First allow me to say that the current Nagios looks *awesome*! Still running a v3.5 build and the differences and improvements are fantastic.
I'm tinkering with the latest NLS VM I downloaded a few days ago, and am impressed with how easy it is to install, but I'm looking for the legendary customization abilities...
Specifically, I don't want to have to manage any more Elasticsearch clusters than necessary. We have one already, but I love the NLS features so much I'd like to ditch it in favor of NLS. So far, I have figured out how to redirect my existing Logstash servers to send to the NLS Elasticsearch server. This made me happy!
I can also create dashboards and queries against the new indices (non "Logstash-") that are being created. Also very cool!
However, I am trying to figure out how to save queries that can be acted upon by Alerts from either NLS or Nagios XI -- it appears built-in logging queries/alerting only act upon the '[logstash-]YYYY.MM.DD' indices, is that correct?
Is there anyway to build an alert-servicecheck against custom indices like '[filebeat-]YYYY.MM.DD'?
I'm not afraid to use vi, just point the way! It's also OK to tell me that NLS won't work for me, but this will make me SAD! I'd love to hear how anyone is using Nagios XI to query logs in non-NLS Elasticsearch clusters too.
Thanks in advance!
Mike