Last active
January 6, 2017 20:24
-
-
Save mrlesmithjr/b0c8f9d8495c8dbefba7 to your computer and use it in GitHub Desktop.
Logstash Syslog Dashboard
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
{ | |
"title": "Syslog", | |
"services": { | |
"query": { | |
"list": { | |
"0": { | |
"query": "*", | |
"alias": "", | |
"color": "#7EB26D", | |
"id": 0, | |
"pin": false, | |
"type": "lucene", | |
"enable": true | |
}, | |
"1": { | |
"id": 1, | |
"color": "#EAB839", | |
"alias": "Invalid User", | |
"pin": true, | |
"type": "lucene", | |
"enable": true, | |
"query": "\"Invalid user\"" | |
}, | |
"2": { | |
"id": 2, | |
"color": "#6ED0E0", | |
"alias": "Failed Password", | |
"pin": true, | |
"type": "lucene", | |
"enable": true, | |
"query": "\"Failed password\"" | |
} | |
}, | |
"ids": [ | |
0, | |
1, | |
2 | |
] | |
}, | |
"filter": { | |
"list": { | |
"0": { | |
"type": "time", | |
"field": "@timestamp", | |
"from": "now-12h", | |
"to": "now", | |
"mandate": "must", | |
"active": true, | |
"alias": "", | |
"id": 0 | |
}, | |
"1": { | |
"type": "terms", | |
"field": "tags", | |
"value": "syslog", | |
"mandate": "must", | |
"active": true, | |
"alias": "", | |
"id": 1 | |
} | |
}, | |
"ids": [ | |
0, | |
1 | |
] | |
} | |
}, | |
"rows": [ | |
{ | |
"title": "Graph", | |
"height": "175px", | |
"editable": true, | |
"collapse": false, | |
"collapsable": true, | |
"panels": [ | |
{ | |
"span": 12, | |
"editable": true, | |
"group": [ | |
"default" | |
], | |
"type": "histogram", | |
"mode": "count", | |
"time_field": "@timestamp", | |
"value_field": null, | |
"auto_int": true, | |
"resolution": 100, | |
"interval": "5m", | |
"fill": 3, | |
"linewidth": 3, | |
"timezone": "browser", | |
"spyable": true, | |
"zoomlinks": true, | |
"bars": true, | |
"stack": false, | |
"points": false, | |
"lines": false, | |
"legend": true, | |
"x-axis": true, | |
"y-axis": true, | |
"percentage": false, | |
"interactive": true, | |
"queries": { | |
"mode": "unpinned", | |
"ids": [ | |
0 | |
] | |
}, | |
"title": "Events over time", | |
"intervals": [ | |
"auto", | |
"1s", | |
"1m", | |
"5m", | |
"10m", | |
"30m", | |
"1h", | |
"3h", | |
"12h", | |
"1d", | |
"1w", | |
"1M", | |
"1y" | |
], | |
"options": true, | |
"tooltip": { | |
"value_type": "cumulative", | |
"query_as_alias": true | |
}, | |
"scale": 1, | |
"y_format": "none", | |
"grid": { | |
"max": null, | |
"min": 0 | |
}, | |
"annotate": { | |
"enable": false, | |
"query": "*", | |
"size": 20, | |
"field": "_type", | |
"sort": [ | |
"_score", | |
"desc" | |
] | |
}, | |
"pointradius": 5, | |
"show_query": true, | |
"legend_counts": true, | |
"zerofill": true, | |
"derivative": false | |
}, | |
{ | |
"error": false, | |
"span": 4, | |
"editable": true, | |
"type": "terms", | |
"loadingEditor": false, | |
"field": "syslog_severity", | |
"exclude": [], | |
"missing": false, | |
"other": false, | |
"size": 10, | |
"order": "count", | |
"style": { | |
"font-size": "10pt" | |
}, | |
"donut": false, | |
"tilt": false, | |
"labels": true, | |
"arrangement": "horizontal", | |
"chart": "bar", | |
"counter_pos": "above", | |
"spyable": true, | |
"queries": { | |
"mode": "unpinned", | |
"ids": [ | |
0 | |
] | |
}, | |
"tmode": "terms", | |
"tstat": "total", | |
"valuefield": "", | |
"title": "Syslog Severities" | |
}, | |
{ | |
"error": false, | |
"span": 4, | |
"editable": true, | |
"type": "terms", | |
"loadingEditor": false, | |
"field": "syslog_program.raw", | |
"exclude": [], | |
"missing": false, | |
"other": false, | |
"size": 10, | |
"order": "count", | |
"style": { | |
"font-size": "10pt" | |
}, | |
"donut": false, | |
"tilt": false, | |
"labels": true, | |
"arrangement": "horizontal", | |
"chart": "bar", | |
"counter_pos": "above", | |
"spyable": true, | |
"queries": { | |
"mode": "unpinned", | |
"ids": [ | |
0 | |
] | |
}, | |
"tmode": "terms", | |
"tstat": "total", | |
"valuefield": "", | |
"title": "Syslog Program" | |
}, | |
{ | |
"error": false, | |
"span": 4, | |
"editable": true, | |
"type": "terms", | |
"loadingEditor": false, | |
"field": "@source_host", | |
"exclude": [], | |
"missing": false, | |
"other": false, | |
"size": 10, | |
"order": "count", | |
"style": { | |
"font-size": "10pt" | |
}, | |
"donut": false, | |
"tilt": false, | |
"labels": true, | |
"arrangement": "horizontal", | |
"chart": "bar", | |
"counter_pos": "above", | |
"spyable": true, | |
"queries": { | |
"mode": "unpinned", | |
"ids": [ | |
0 | |
] | |
}, | |
"tmode": "terms", | |
"tstat": "total", | |
"valuefield": "", | |
"title": "Top 10 Sources" | |
} | |
], | |
"notice": false | |
}, | |
{ | |
"title": "Events", | |
"height": "350px", | |
"editable": true, | |
"collapse": false, | |
"collapsable": true, | |
"panels": [ | |
{ | |
"title": "All events", | |
"error": false, | |
"span": 12, | |
"editable": true, | |
"group": [ | |
"default" | |
], | |
"type": "table", | |
"size": 100, | |
"pages": 5, | |
"offset": 0, | |
"sort": [ | |
"@timestamp", | |
"desc" | |
], | |
"style": { | |
"font-size": "9pt" | |
}, | |
"overflow": "min-height", | |
"fields": [ | |
"@timestamp", | |
"@source_host", | |
"@message", | |
"syslog_severity", | |
"syslog_facility", | |
"tags" | |
], | |
"localTime": true, | |
"timeField": "@timestamp", | |
"highlight": [], | |
"sortable": true, | |
"header": true, | |
"paging": true, | |
"spyable": true, | |
"queries": { | |
"mode": "unpinned", | |
"ids": [ | |
0 | |
] | |
}, | |
"field_list": true, | |
"status": "Stable", | |
"trimFactor": 300, | |
"normTimes": true, | |
"all_fields": false | |
} | |
], | |
"notice": false | |
} | |
], | |
"editable": true, | |
"failover": false, | |
"index": { | |
"interval": "day", | |
"pattern": "[logstash-]YYYY.MM.DD", | |
"default": "NO_TIME_FILTER_OR_INDEX_PATTERN_NOT_MATCHED", | |
"warm_fields": true | |
}, | |
"style": "dark", | |
"panel_hints": true, | |
"pulldowns": [ | |
{ | |
"type": "query", | |
"collapse": true, | |
"notice": false, | |
"query": "*", | |
"pinned": true, | |
"history": [ | |
"\"Failed password\"", | |
"\"Invalid user\"", | |
"*", | |
"syslog_program:sshd", | |
"message:\"Failed password\"", | |
"message: \"Failed password\"", | |
"syslog_program:sshd AND message: \"Failed password\"", | |
"syslog_program:sshd AND message: \"Failed\"", | |
"syslog_program IS sshd AND @message CONTAINS Failed", | |
"syslog_program:sshd AND @message CONTAINS Failed" | |
], | |
"remember": 10, | |
"enable": true | |
}, | |
{ | |
"type": "filtering", | |
"collapse": true, | |
"notice": false, | |
"enable": true | |
} | |
], | |
"nav": [ | |
{ | |
"type": "timepicker", | |
"collapse": false, | |
"notice": false, | |
"status": "Stable", | |
"time_options": [ | |
"5m", | |
"15m", | |
"1h", | |
"6h", | |
"12h", | |
"24h", | |
"2d", | |
"7d", | |
"30d" | |
], | |
"refresh_intervals": [ | |
"5s", | |
"10s", | |
"30s", | |
"1m", | |
"5m", | |
"15m", | |
"30m", | |
"1h", | |
"2h", | |
"1d" | |
], | |
"timefield": "@timestamp", | |
"now": true, | |
"filter_id": 0, | |
"enable": true | |
} | |
], | |
"loader": { | |
"save_gist": false, | |
"save_elasticsearch": true, | |
"save_local": true, | |
"save_default": true, | |
"save_temp": true, | |
"save_temp_ttl_enable": true, | |
"save_temp_ttl": "30d", | |
"load_gist": true, | |
"load_elasticsearch": true, | |
"load_elasticsearch_size": 20, | |
"load_local": true, | |
"hide": false | |
}, | |
"refresh": "5m" | |
} |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment