Hello,
can some expert help me to estimate in man/days, to setup ELK stack in one evnironment?
Data on-boarding of system matrix from 40 clients.
Writing Groke patterns for 5 different patterns
Configuration of Logstash-Kibana-ES
Installation of x-pack
Creating visualizations: Host overview, System-Overview using Guage/bar charts/Timeseries using Visual builder
and some ad-hoc tasks and unforeseen issues
How much time I need to do this all?
I want expert opinion considering some practical issues they faced in their experience. Please comment.
This is almost impossible to answer as it depends a lot on how truly "expert" the person doing the work is, and how much of the solution the expert has "pre-developed".
For example we recently deployed a five node ES cluster, with a 3 node Kafka cluster (incl. 3 node Zookeeper) on the ingest side, and a single node monitoring instance, tapped into a datafeed from Azure IoT Hub and built the first dashboards... all done by one person in a single day. To do so requires a lot of experience with the platforms, and a lot of preconfigured bits to start from.
The same goes for handling data sources. Take something as supposedly simple as syslog. Our parsing of the just the header portion of a syslog message can handle all the most common structures you will see. But it also handles 30+ "wierd ways vendors abuse syslog". So in just a few minutes we can setup syslog handling that will reliably handle a wide variety of messages thrown at it, where others could spend a day or two just figuring out all the variations of timestamp that they will have to deal with.
In case you are wondering, this is the regex for all of the variations of timestamp we have seen...
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.