ELK (Elasticsearch + Logstash + Kibana) is fun!
Logstash is super flexible, most operations can be.
Start separately Java process, shipper indexer. (divided into two by copying the startup script that is distributed in the package version)
-
postfix grok patterns :
-
sshd grok patterns :
-
https://github.com/autosportlabs/docker-logstash/blob/master/src/conf/520-mogrify-sshd.conf
-
Lightweight log shipper : logstash-forwarder (aka lumberjack)
-
grok filter ruby :
-
https://groups.google.com/forum/#!topic/logstash-users/iEYRv7bCqdM
-
kibana geoip BetterMap :
-
grok apache User-Agent :
-
http://untergeek.com/2013/09/11/getting-apache-to-output-json-for-logstash-1-2-x/
-
https://github.com/ua-parser/uap-core/blob/master/regexes.yaml
-
Integrating DataDog
-
http://ifdattic.com/integrating-datadog-and-logstash-on-aws-ec2/
-
zimbra mailbox.log & zimbra.log (amavis)
-
http://blog.itlinux.cl/blog/2015/05/25/buscando-mensajes-de-correo-con-kibana/
-
https://wiki.zimbra.com/wiki/Centralized_Logs_-_Elasticsearch,_Logstash_and_Kibana
-
https://blog.zimbra.com/2007/05/mailboxlog-the-king-of-zimbra-log-files/
-
https://www.zimbra.com/docs/os/5.0.19/administration_guide/9_Monitoring.11.1.html