Top Banner
Hart Hoover | @hhoover Josh O’Brien | @OBrienCommaJosh @SADevOps
25

San Antonio DevOps: Fluentd

Jul 16, 2015

Download

Technology

Hart Hoover
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: San Antonio DevOps: Fluentd

Hart Hoover | @hhoover Josh O’Brien | @OBrienCommaJosh

@SADevOps

Page 2: San Antonio DevOps: Fluentd

fluentd

Page 3: San Antonio DevOps: Fluentd

Log all the thingsto all the things!

Page 4: San Antonio DevOps: Fluentd

…in JSON!

Page 5: San Antonio DevOps: Fluentd
Page 6: San Antonio DevOps: Fluentd
Page 7: San Antonio DevOps: Fluentd
Page 8: San Antonio DevOps: Fluentd

input&{&&&file&{&&&&&path&=>&"/var/log/http.log"&&&}&}&filter&{&&&grok&{&&&&&match&=>&[&"message",&"%{IP:client}&%{WORD:method}&%{URIPATHPARAM:request}&%{NUMBER:bytes}&%{NUMBER:duration}"&]&&&}&}

Page 9: San Antonio DevOps: Fluentd
Page 10: San Antonio DevOps: Fluentd
Page 11: San Antonio DevOps: Fluentd
Page 12: San Antonio DevOps: Fluentd

Fluentd Events

Time Tag

Record

passed from source or

adding a parsed time

message routing in fluentd

JSON

Page 13: San Antonio DevOps: Fluentd

#&receive&events&via&HTTP&&<source>&&type&http&&port&8888&&</source>

Page 14: San Antonio DevOps: Fluentd

#&read&logs&from&a&file&&<source>&&type&tailpath&/var/log/httpd.log&format&apachetag&apache.access&&</source>

Page 15: San Antonio DevOps: Fluentd

#&DOCKER&OMG&<source>&&&type&tail&&&format&json&&&path&/var/lib/docker/containers/ID/IDYjson.log&&&pos_file&/var/lib/docker/containers/ID/IDYjson.log.pos&&&tag&docker.container&&&rotate_wait&5&&&read_from_head&true&</source>

Page 16: San Antonio DevOps: Fluentd

#&save&alerts&to&a&file&&<match&alert.**>&&type&file&&path&/var/log/fluent/alerts&&</match>

Page 17: San Antonio DevOps: Fluentd

#&save&access&logs&to&MongoDB&&<match&apache.access>&&type&mongo&database&apache&collection&log&&</match>&

Page 18: San Antonio DevOps: Fluentd

#&Post&to&IRC&<match&**>&&&type&irc&&&host&localhost&&&port&6667&&&channel&fluentd&&&nick&fluentd&&&user&fluentd&&&real&fluentd&&&message&notice:&%s&[%s]&%s&&&out_keys&tag,time,message&&&time_key&time&&&time_format&%Y/%m/%d&%H:%M:%S&&&tag_key&tag&</match>

Page 19: San Antonio DevOps: Fluentd

#&forward&other&logs&to&servers&&<match&**>&&type&forward&&&<server>&&&&&&host&192.168.0.11&&&&&&weight&20&&&&</server>&&&<server>&&&&&&host&192.168.0.12&&&&&&weight&60&&&&</server></match>

Page 20: San Antonio DevOps: Fluentd

#&Send&logs&to&ElasticSearch&<match&**>&&&type&elasticsearch&&&logstash_format&true&&&host&localhost&&&port&9200&&&index_name&fluentd&</match>

Page 21: San Antonio DevOps: Fluentd
Page 22: San Antonio DevOps: Fluentd

Client LibrariesRuby

Python Java PHP

Node.JS Scala

Page 23: San Antonio DevOps: Fluentd

https://github.com/treasure-data/chef-td-agent

Install with Chef

Vagrantfile & kitchen.yml included!

Page 24: San Antonio DevOps: Fluentd

https://github.com/dmytro/fluentd-cookbook

Possibly Better

https://gist.github.com/hhoover/4fceb09148a73f45136a

Page 25: San Antonio DevOps: Fluentd

@SADevOpshttp://meetup.com/SanAntonioDevOps