Hello,
We currently use Logwatch in our Server Farm to have a daily report of all
the logs of all the machines.
The problem is that receiving everyday hundred of email makes it difficult
to go through all them.
We were looking something similiar to Splunk, that allow us to easily query
all the collected logs, and be daily informed for example about who failed
to login more than 3 times on our machine, or how many packages hae been
rejected from the firewall and from and to which ports etc... (Hope I gave
the idea of what we need).
As I said Splunk was really good on how to query those kind of data, but
it's too expensive and actually it does even too much (we don't need graph,
GUI to check the data in real time etc).
Of course by checking on the web for an alternative, Elasticsearch and
Logstash names came out.
I really like logstash as it helps you to filter out stuff and better
categorize the data (for a better future query), but my problem is that I
have a central Logstash server that receive all the logs from rsyslog, and
in this way I can't separate the kind of data like for example sshd logs
from firewall one etc.
Also I dont like at all Elasticsearch, the query system seem to much
"complicated" even to simply query a normal document, it became really
trick when it's up to do something like exaplained before, and there is no
way to have a report of the logs queried, if not by writing some script to
parse the Json, and depending of whih kind of logs, regx and re-write the
text to have an understandable email report, and send it.
Does anybody got any suggestion?
--
You received this message because you are subscribed to the Google Groups "elasticsearch" group.
To unsubscribe from this group and stop receiving emails from it, send an email to elasticsearch+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/elasticsearch/2ef6f964-e2b7-4f75-bcbe-9eb8b4b3658d%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.