Created
May 6, 2014 16:16
-
-
Save rshk/23ff4b0c162ba4b8a326 to your computer and use it in GitHub Desktop.
Kibana: analyze Apache logs
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
{ | |
"title": "Apache logs", | |
"services": { | |
"query": { | |
"list": { | |
"0": { | |
"query": "*", | |
"alias": "", | |
"color": "#7EB26D", | |
"id": 0, | |
"pin": false, | |
"type": "lucene", | |
"enable": true | |
} | |
}, | |
"ids": [ | |
0 | |
] | |
}, | |
"filter": { | |
"list": { | |
"0": { | |
"type": "time", | |
"field": "@timestamp", | |
"from": "now-7d", | |
"to": "now", | |
"mandate": "must", | |
"active": true, | |
"alias": "", | |
"id": 0 | |
} | |
}, | |
"ids": [ | |
0 | |
] | |
} | |
}, | |
"rows": [ | |
{ | |
"title": "", | |
"height": "150px", | |
"editable": true, | |
"collapse": false, | |
"collapsable": true, | |
"panels": [ | |
{ | |
"span": 12, | |
"editable": true, | |
"type": "histogram", | |
"loadingEditor": false, | |
"mode": "count", | |
"time_field": "@timestamp", | |
"value_field": null, | |
"x-axis": true, | |
"y-axis": true, | |
"scale": 1, | |
"y_format": "none", | |
"grid": { | |
"max": null, | |
"min": 0 | |
}, | |
"queries": { | |
"mode": "all", | |
"ids": [ | |
0 | |
] | |
}, | |
"annotate": { | |
"enable": false, | |
"query": "*", | |
"size": 20, | |
"field": "_type", | |
"sort": [ | |
"_score", | |
"desc" | |
] | |
}, | |
"auto_int": true, | |
"resolution": 100, | |
"interval": "1h", | |
"intervals": [ | |
"auto", | |
"1s", | |
"1m", | |
"5m", | |
"10m", | |
"30m", | |
"1h", | |
"3h", | |
"12h", | |
"1d", | |
"1w", | |
"1y" | |
], | |
"lines": true, | |
"fill": 0, | |
"linewidth": 3, | |
"points": false, | |
"pointradius": 5, | |
"bars": false, | |
"stack": true, | |
"spyable": true, | |
"zoomlinks": true, | |
"options": true, | |
"legend": true, | |
"show_query": true, | |
"interactive": true, | |
"legend_counts": true, | |
"timezone": "browser", | |
"percentage": false, | |
"zerofill": true, | |
"derivative": false, | |
"tooltip": { | |
"value_type": "cumulative", | |
"query_as_alias": true | |
} | |
} | |
], | |
"notice": false | |
}, | |
{ | |
"title": "Requests", | |
"height": "150px", | |
"editable": true, | |
"collapse": false, | |
"collapsable": true, | |
"panels": [ | |
{ | |
"error": false, | |
"span": 3, | |
"editable": true, | |
"type": "terms", | |
"loadingEditor": false, | |
"field": "verb", | |
"exclude": [], | |
"missing": true, | |
"other": true, | |
"size": 10, | |
"order": "count", | |
"style": { | |
"font-size": "10pt" | |
}, | |
"donut": false, | |
"tilt": false, | |
"labels": true, | |
"arrangement": "horizontal", | |
"chart": "pie", | |
"counter_pos": "above", | |
"spyable": true, | |
"queries": { | |
"mode": "all", | |
"ids": [ | |
0 | |
] | |
}, | |
"tmode": "terms", | |
"tstat": "total", | |
"valuefield": "", | |
"title": "HTTP Method" | |
}, | |
{ | |
"error": false, | |
"span": 6, | |
"editable": true, | |
"type": "terms", | |
"loadingEditor": false, | |
"field": "request", | |
"exclude": [], | |
"missing": true, | |
"other": true, | |
"size": 10, | |
"order": "count", | |
"style": { | |
"font-size": "10pt" | |
}, | |
"donut": false, | |
"tilt": false, | |
"labels": true, | |
"arrangement": "horizontal", | |
"chart": "bar", | |
"counter_pos": "above", | |
"spyable": true, | |
"queries": { | |
"mode": "all", | |
"ids": [ | |
0 | |
] | |
}, | |
"tmode": "terms", | |
"tstat": "total", | |
"valuefield": "", | |
"title": "Request" | |
}, | |
{ | |
"error": false, | |
"span": 3, | |
"editable": true, | |
"type": "terms", | |
"loadingEditor": false, | |
"field": "response", | |
"exclude": [], | |
"missing": true, | |
"other": true, | |
"size": 10, | |
"order": "count", | |
"style": { | |
"font-size": "10pt" | |
}, | |
"donut": false, | |
"tilt": false, | |
"labels": true, | |
"arrangement": "horizontal", | |
"chart": "pie", | |
"counter_pos": "above", | |
"spyable": true, | |
"queries": { | |
"mode": "all", | |
"ids": [ | |
0 | |
] | |
}, | |
"tmode": "terms", | |
"tstat": "total", | |
"valuefield": "", | |
"title": "Response code" | |
} | |
], | |
"notice": false | |
}, | |
{ | |
"title": "UA/Referrer", | |
"height": "150px", | |
"editable": true, | |
"collapse": false, | |
"collapsable": true, | |
"panels": [ | |
{ | |
"error": false, | |
"span": 6, | |
"editable": true, | |
"type": "terms", | |
"loadingEditor": false, | |
"field": "agent", | |
"exclude": [], | |
"missing": true, | |
"other": true, | |
"size": 10, | |
"order": "count", | |
"style": { | |
"font-size": "10pt" | |
}, | |
"donut": false, | |
"tilt": false, | |
"labels": true, | |
"arrangement": "horizontal", | |
"chart": "bar", | |
"counter_pos": "above", | |
"spyable": true, | |
"queries": { | |
"mode": "all", | |
"ids": [ | |
0 | |
] | |
}, | |
"tmode": "terms", | |
"tstat": "total", | |
"valuefield": "", | |
"title": "User Agent" | |
}, | |
{ | |
"error": false, | |
"span": 6, | |
"editable": true, | |
"type": "terms", | |
"loadingEditor": false, | |
"field": "referrer", | |
"exclude": [], | |
"missing": true, | |
"other": true, | |
"size": 10, | |
"order": "count", | |
"style": { | |
"font-size": "10pt" | |
}, | |
"donut": false, | |
"tilt": false, | |
"labels": true, | |
"arrangement": "horizontal", | |
"chart": "bar", | |
"counter_pos": "above", | |
"spyable": true, | |
"queries": { | |
"mode": "all", | |
"ids": [ | |
0 | |
] | |
}, | |
"tmode": "terms", | |
"tstat": "total", | |
"valuefield": "", | |
"title": "Referrer" | |
} | |
], | |
"notice": false | |
}, | |
{ | |
"title": "", | |
"height": "150px", | |
"editable": true, | |
"collapse": false, | |
"collapsable": true, | |
"panels": [ | |
{ | |
"error": false, | |
"span": 12, | |
"editable": true, | |
"type": "table", | |
"loadingEditor": false, | |
"size": 100, | |
"pages": 5, | |
"offset": 0, | |
"sort": [ | |
"_score", | |
"desc" | |
], | |
"overflow": "min-height", | |
"fields": [ | |
"@timestamp", | |
"agent", | |
"clientip", | |
"referrer", | |
"verb", | |
"request", | |
"response" | |
], | |
"highlight": [], | |
"sortable": true, | |
"header": true, | |
"paging": true, | |
"field_list": true, | |
"all_fields": false, | |
"trimFactor": 300, | |
"localTime": false, | |
"timeField": "@timestamp", | |
"spyable": true, | |
"queries": { | |
"mode": "all", | |
"ids": [ | |
0 | |
] | |
}, | |
"style": { | |
"font-size": "9pt" | |
}, | |
"normTimes": true | |
} | |
], | |
"notice": false | |
} | |
], | |
"editable": true, | |
"failover": false, | |
"index": { | |
"interval": "none", | |
"pattern": "[logstash-]YYYY.MM.DD", | |
"default": "dti-apache-logs", | |
"warm_fields": false | |
}, | |
"style": "dark", | |
"panel_hints": true, | |
"pulldowns": [ | |
{ | |
"type": "query", | |
"collapse": false, | |
"notice": false, | |
"enable": true, | |
"query": "*", | |
"pinned": true, | |
"history": [], | |
"remember": 10 | |
}, | |
{ | |
"type": "filtering", | |
"collapse": false, | |
"notice": true, | |
"enable": true | |
} | |
], | |
"nav": [ | |
{ | |
"type": "timepicker", | |
"collapse": false, | |
"notice": false, | |
"enable": true, | |
"status": "Stable", | |
"time_options": [ | |
"5m", | |
"15m", | |
"1h", | |
"6h", | |
"12h", | |
"24h", | |
"2d", | |
"7d", | |
"30d" | |
], | |
"refresh_intervals": [ | |
"5s", | |
"10s", | |
"30s", | |
"1m", | |
"5m", | |
"15m", | |
"30m", | |
"1h", | |
"2h", | |
"1d" | |
], | |
"timefield": "@timestamp", | |
"now": true, | |
"filter_id": 0 | |
} | |
], | |
"loader": { | |
"save_gist": false, | |
"save_elasticsearch": true, | |
"save_local": true, | |
"save_default": true, | |
"save_temp": true, | |
"save_temp_ttl_enable": true, | |
"save_temp_ttl": "30d", | |
"load_gist": false, | |
"load_elasticsearch": true, | |
"load_elasticsearch_size": 20, | |
"load_local": false, | |
"hide": false | |
}, | |
"refresh": false | |
} |
I'm trying to use this in Kibana but I get an error when I load this dashboard
IndexMissingException[[dti-apache-logs] missing]
Any ideas what is contained in this index and how to create it? Would be really helpful in debugging.
Thanks!
The index has to be my-logs and not dti-apache-logs if you are referring to http://www.hackzine.org/importing-apache-logs-in-elasticsearch.html
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
I'm using kibana 4. How to import this dashboard in my kibana ?