/logstash

Configurations of my logstash: logstash, filebeat, grok patterns: sshd, postfix, apache, sysdig, zimbra mailbox.log, zimbra zimbra.log, Datadog Dogstatsd, fail2ban

logstash

my logsash config

ELK (Elasticsearch + Logstash + Kibana) is fun!

Logstash is super flexible, most operations can be.

memo

Start separately Java process, shipper indexer. (divided into two by copying the startup script that is distributed in the package version)

reference

postfix grok patterns :

sshd grok patterns :

Lightweight log shipper : logstash-forwarder (aka lumberjack)

grok filter ruby :

kibana geoip BetterMap :

grok apache User-Agent :

Integrating DataDog

zimbra mailbox.log & zimbra.log (amavis)