Warning: This is essentially a brain dump, so it is more like a set of notes than a tutorial as such. I’m planning to clean this up and develop it as I go along. It’s incomplete. I’m publishing this, because otherwise it will sit as a draft probably forever. This is mostly me talking myself through troubleshooting, I do that a lot. Read the rest of this entry »
A while ago I ran into an issue where I couldnt use Logstash and the ‘logstash-input-s3’ plugin, and the manual authentication method didnt work well.
I previously wrote about making a grok filter to process ELB logs.
I have since worked on this further and developed an updated filter, which has been working very well for some time now.
As there were some comments on the previous post, I thought I should upload my working copy that I use right now also.
Read the rest of this entry »
I recently ran into a problem with Logstash, where it would not correctly and consistently process AWS (Amazon Web Services) ELB (Elastic Load Balancer) logs from an S3 bucket.
ELB logs are the standard method of logging ELB usage and activity in AWS, and are very useful when trying to determine a wide variety of trends and activities.
I was determined to get ELB logs into Elasticsearch, using logstash, so I needed to figure out a few things… Read the rest of this entry »
Where I work we aggregate all of our AWS CloudTrail logs from separate accounts into a single S3 bucket in a central account.
Yesterday, I ran into a weird problem where I noticed that our Logging solution, ELK, would not process files dating before a certain time.
Upon further investigation, I discovered that the date period missing was before we moved all of our existing files into the bucket from the AWS account it was originally in. So, “simple!” I thought to myself, “I’ll just update the permissions and allow ELK access to the files!”.
I was wrong, not simple. I had to fix this anyway… Read the rest of this entry »
I develop and run quite a few little network scripts to automate repetitive and mundane tasks, and I try as much as possible to do this remotely, without requiring to log onto a particular machine.
I recently ran into a Powershell error that prevented enabling remote Powershell Script running, using the command Enable-PSRemoting. Read the rest of this entry »