Is there anyone out there combining an IPAM with Kibana, ES or logstash ?
I'm looking for a way to group syslog-messages and maybe beats data based on host or subnet.
We have one or more vlans for an application in an IPAM which I can talk to over a rest api.
There are 1175 subnets each with a description VLAN tag, netmask etc.
For example out of IPAM I can symlink the subnet to it's description on my syslog server.
DRAC_Management -> /opt/syslog-ng/logs/192_168_255_44
ASA_Management -> /opt/syslog-ng/logs/192_168_254_84
VMware_management -> /opt/syslog-ng/logs/192_168_255_0
OpenStack_management -> /opt/syslog-ng/logs/192_168_255_4
Apache_roll_A09_2 -> /opt/syslog-ng/logs/192_168_255_8
Product_X_web -> /opt/syslog-ng/logs/192_168_255_12
What's the best way to create these groupings ?