Powering Monitoring Analytics with ELK stack - INRIA - Institut National de Recherche en Informatique et en Automatique Accéder directement au contenu
Document Associé À Des Manifestations Scientifiques Année : 2015

Powering Monitoring Analytics with ELK stack

Frédéric Beck

Résumé

Machine-generated data, including logs and network flows, are considerably growing and their collection, searching, and visualization is a challenging task for (a) daily administrator activities and (b) researchers aiming to better find out analytics and insights from monitoring data regarding their research goals, including amongst others security or modeling of network and systems. This tutorial introduces the open source ELK stack and its components, including Elasticsearch for deep search and data analytics, Logstash for centralized logging, log enrichment, and parsing, and Kibana for powerful and beautiful data visualizations. ELK enables the analysis and visualization of monitoring data, such as logs and netflows. The first part of the tutorial details these individual components. The second part provides guidelines for the deployment and configuration of ELK components. In the third part participants will perform hands-on practical work for collecting, processing, and enriching logs and netflows, combined with the creation of associated visualization and dashboards aspects.
Fichier principal
Vignette du fichier
slides-ELK.pdf (737.12 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-01212015 , version 1 (05-10-2015)

Identifiants

  • HAL Id : hal-01212015 , version 1

Citer

Abdelkader Lahmadi, Frédéric Beck. Powering Monitoring Analytics with ELK stack. 9th International Conference on Autonomous Infrastructure, Management and Security (AIMS 2015), Jun 2015, Ghent, Belgium. 9th International Conference on Autonomous Infrastructure, Management and Security (AIMS 2015), 2015. ⟨hal-01212015⟩
1621 Consultations
4192 Téléchargements

Partager

Gmail Facebook X LinkedIn More