• Save
Using Logstash for Alfresco Audit reporting
 

Using Logstash for Alfresco Audit reporting

on

  • 1,196 views

Using Logstash for Alfresco Audit reporting

Using Logstash for Alfresco Audit reporting

Statistics

Views

Total Views
1,196
Views on SlideShare
1,196
Embed Views
0

Actions

Likes
2
Downloads
3
Comments
0

0 Embeds 0

No embeds

Accessibility

Categories

Upload Details

Uploaded via as Microsoft PowerPoint

Usage Rights

© All Rights Reserved

Report content

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate.

Cancel
  • Full Name Full Name Comment goes here.
    Are you sure you want to
    Your message goes here
    Processing…
Post Comment
Edit your comment

Using Logstash for Alfresco Audit reporting Using Logstash for Alfresco Audit reporting Presentation Transcript

  • Implementing a Log monitoring tool Duminda Ekanayake (dekanayake@zaizi.com)
  • Why it is important • Enterprise systems produce large , different log files. • When you have lot of logs it is very difficult to trace an issue or incident . • Using log files it is possible to alert users when a critical issue is occurred.
  • Features of a good log monitoring tool • Providing a centralized server , where log from nodes are possible to upload • Ability to search specific terms in logs. • Produce alerts on specific log event, ex : when log priority is “ERROR”.
  • Approach
  • Approach • • • • Log4j Logstash Elastic search Kibana
  • Approach
  • Log4j • Add a SocketAppender named LOGSTASH to the applications lo4j.xml file <appender name="LOGSTASH" class="org.apache.log4j.net.SocketAppender"> <param name="RemoteHost" value="your_logstash_host_address" /> <param name="ReconnectionDelay" value="60000" /> <param name="Threshold" value="DEBUG" /> </appender>
  • Logstash • Logstash will collect logs , parse them , and store them for later use (like , searching). input { log4j { type => "log4j-type" port => 4560 } } output { elasticsearch { host => localhost port => 9300 cluster => elasticsearch } }
  • Elastic search • Elastic search is used to store and index logs. • Elastic search – – – – Build on top Lucene Schema free Store as structured JSON documents Real time data and analytics
  • Kibana • Kibana will be use to search the logs • Using Kibana, user’s can – Search the logs – Visually analyze trends in log vloume to find peaks and valleys – Score, trend and average fields to find patterns – Providning RS feed and get updates at any interval
  • SEARCH
  • COLUMNIZE
  • GRAPH
  • SCORE , TRENDS