Host/Beats Agent Table


(Walker) #1

Is it possible to configure a table that reports either # of events received or just the presence of the agent on the host?

Host	AuditBeat	FileBeat	MetricBeat	PacketBeat	WinLogbeat
Host 1					
Host 2					
Host 3

(Bill McConaghy) #2

Since each beat type writes to a different index, not sure how to get a single chart that does what you are looking for. Per beat, you could do a terms aggregation on host for x axis and count aggregation for y and that would display all the hosts you were getting beat data from for that type. It would not show you hosts that had not reported any data as there aren't documents from those hosts in the index. Hope this helps.


(Walker) #3

Blah….kinda figured that was gonna be the answer. Would be a nice feature to have, some sort of beats monitor that you could build this sort of data out of.

Thanks
Bill Walker
Information Technology Security Analyst
St. Louis County Government

Desk: (314) 615-5164
Mobile: (618) 610-5636


(Christian Dahlqvist) #4

You may actually be able to do it through a table visualisation created through time-series visual builder.

Under Panel Options, set Index Pattern to *beat-* to catch all Beats related indices.

Under Columns, select beat.hostname as the Group By Field.

Then create a column for each type of beat you have deployed. Select a Count aggregation and under Option you then add an appropriate filter, e.g. beat.name: filebeat.

This may need a bit of tweaking, but might actually work.


(Walker) #5

Seems like that would work but my config isn’t correct somewhere with the Beats I think. Looking at Discover, beat.name is showing the hostname the agent is on. I looked at the MetricBeat reference, but a setting isn’t jumping out at me that allows me to specify that field. Any idea what that would be?

Thanks
Bill Walker
Information Technology Security Analyst
St. Louis County Government

Desk: (314) 615-5164
Mobile: (618) 610-5636


(system) #6

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.