Kibana Monitoring Overview of the Elastic Stack components
Slide 41
Metricbeat System [Metricbeat System] Overview and [Metricbeat System] Host overview dashboards See the memory spike every 5min
Slide 42
Time Series Visual Builder Sum of system.memory.actual.used.bytes Sum of system.process.memory. rss.bytes grouped by the term system.process.name and moved to the negative y-axis with a Math step
Slide 43
Slide 44
Packetbeat Call /, /good, /bad, and /foobar [Packetbeat] Overview, [Packetbeat] Flows, [Packetbeat] HTTP, and [Packetbeat] DNS Tunneling dashboards
Slide 45
Packetbeat Raw events in Discover Process enrichment for nginx, Java, and the APM server
Slide 46
Filebeat Modules [Filebeat Nginx] Access and error logs, [Filebeat System] Syslog dashboard, and [Osquery Result] Compliance pack dashboards
Slide 47
Custom Log Files
Slide 48
Elastic Common Schema https://github.com/elastic/ecs
Slide 49
Slide 50
Dev Tools
Grok Debugger
Slide 51
Machine Learning
Data Visualizer
Slide 52
Log UI
Slide 53
Infra UI
Slide 54
Filebeat Raw events in Discover /good: MDC logging under json.name and the context view for one log message meta.* and host.* information
Slide 55
Filebeat /bad and /null: Stacktraces by filtering down on application:java and json.severity:ERROR Visualize json.stack_hash
Slide 56
Slide 57
Heartbeat Heartbeat HTTP monitoring dashboard Stop and start the frontend application while auto refreshing
Metricbeat HTTP /health and /metrics endpoints Collected information in Discover
Slide 60
Metricbeat JMX Same data Visualize the heap usage: jolokia. metrics.memory.heap_usage.used divided by the max of jolokia. metrics.memory.heap_usage.max
Slide 61
Annotations Add changes from the events index
Slide 62
Slide 63
Slide 64
APM Distributed Tracing
Slide 65
Some Security
Slide 66
Filebeat Modules [Filebeat Auditd] Audit Events, [Filebeat System] New users and groups, and [Filebeat System] Sudo commands dashboards
Slide 67
https://github.com/linux-audit "auditd is the userspace component to the Linux Auditing System. It's responsible for writing audit records to the disk. Viewing the logs is done with the ausearch or aureport utilities."
Slide 68
Auditd Monitors File and network access System calls Commands run by a user Security events