527 lines
15 KiB
JSON
527 lines
15 KiB
JSON
{
|
|
"__inputs": [
|
|
{
|
|
"name": "DS_OPENSEARCH",
|
|
"label": "OpenSearch",
|
|
"description": "",
|
|
"type": "datasource",
|
|
"pluginId": "grafana-opensearch-datasource",
|
|
"pluginName": "OpenSearch"
|
|
}
|
|
],
|
|
"__elements": {},
|
|
"__requires": [
|
|
{
|
|
"type": "grafana",
|
|
"id": "grafana",
|
|
"name": "Grafana",
|
|
"version": "11.6.3"
|
|
},
|
|
{
|
|
"type": "datasource",
|
|
"id": "grafana-opensearch-datasource",
|
|
"name": "OpenSearch",
|
|
"version": "2.27.0"
|
|
},
|
|
{
|
|
"type": "panel",
|
|
"id": "table",
|
|
"name": "Table",
|
|
"version": ""
|
|
}
|
|
],
|
|
"annotations": {
|
|
"list": [
|
|
{
|
|
"builtIn": 1,
|
|
"datasource": {
|
|
"type": "grafana",
|
|
"uid": "-- Grafana --"
|
|
},
|
|
"enable": true,
|
|
"hide": true,
|
|
"iconColor": "rgba(0, 211, 255, 1)",
|
|
"name": "Annotations & Alerts",
|
|
"type": "dashboard"
|
|
}
|
|
]
|
|
},
|
|
"editable": true,
|
|
"fiscalYearStartMonth": 0,
|
|
"graphTooltip": 0,
|
|
"id": null,
|
|
"links": [],
|
|
"panels": [
|
|
{
|
|
"datasource": {
|
|
"type": "grafana-opensearch-datasource",
|
|
"uid": "OpenSearch-Opengnsys"
|
|
},
|
|
"fieldConfig": {
|
|
"defaults": {
|
|
"color": {
|
|
"mode": "thresholds"
|
|
},
|
|
"custom": {
|
|
"align": "auto",
|
|
"cellOptions": {
|
|
"type": "auto"
|
|
},
|
|
"inspect": false
|
|
},
|
|
"mappings": [],
|
|
"thresholds": {
|
|
"mode": "absolute",
|
|
"steps": [
|
|
{
|
|
"color": "green"
|
|
},
|
|
{
|
|
"color": "red",
|
|
"value": 80
|
|
}
|
|
]
|
|
}
|
|
},
|
|
"overrides": [
|
|
{
|
|
"matcher": {
|
|
"id": "byName",
|
|
"options": "agent.type"
|
|
},
|
|
"properties": [
|
|
{
|
|
"id": "custom.width",
|
|
"value": 121
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"matcher": {
|
|
"id": "byName",
|
|
"options": "message_decoded.message"
|
|
},
|
|
"properties": [
|
|
{
|
|
"id": "custom.width",
|
|
"value": 1250
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"matcher": {
|
|
"id": "byName",
|
|
"options": "@timestamp"
|
|
},
|
|
"properties": [
|
|
{
|
|
"id": "custom.width",
|
|
"value": 193
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"matcher": {
|
|
"id": "byName",
|
|
"options": "message"
|
|
},
|
|
"properties": [
|
|
{
|
|
"id": "custom.width",
|
|
"value": 1725
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"matcher": {
|
|
"id": "byName",
|
|
"options": "host.os.type"
|
|
},
|
|
"properties": [
|
|
{
|
|
"id": "custom.width",
|
|
"value": 42
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"matcher": {
|
|
"id": "byName",
|
|
"options": "data_json"
|
|
},
|
|
"properties": [
|
|
{
|
|
"id": "custom.width",
|
|
"value": 359
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"matcher": {
|
|
"id": "byName",
|
|
"options": "message_decoded.severity"
|
|
},
|
|
"properties": [
|
|
{
|
|
"id": "custom.width",
|
|
"value": 203
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"matcher": {
|
|
"id": "byName",
|
|
"options": "host.hostname"
|
|
},
|
|
"properties": [
|
|
{
|
|
"id": "custom.width",
|
|
"value": 159
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"matcher": {
|
|
"id": "byName",
|
|
"options": "host.ip"
|
|
},
|
|
"properties": [
|
|
{
|
|
"id": "custom.width",
|
|
"value": 177
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"matcher": {
|
|
"id": "byName",
|
|
"options": "host.mac"
|
|
},
|
|
"properties": [
|
|
{
|
|
"id": "custom.width",
|
|
"value": 369
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"matcher": {
|
|
"id": "byName",
|
|
"options": "data_decoded.job_id"
|
|
},
|
|
"properties": [
|
|
{
|
|
"id": "custom.width",
|
|
"value": 240
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"matcher": {
|
|
"id": "byName",
|
|
"options": "data_decoded.secret"
|
|
},
|
|
"properties": [
|
|
{
|
|
"id": "custom.width",
|
|
"value": 217
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"matcher": {
|
|
"id": "byName",
|
|
"options": "parsed_message.desc"
|
|
},
|
|
"properties": [
|
|
{
|
|
"id": "custom.width",
|
|
"value": 1266
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"matcher": {
|
|
"id": "byName",
|
|
"options": "fecha"
|
|
},
|
|
"properties": [
|
|
{
|
|
"id": "custom.width",
|
|
"value": 427
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"matcher": {
|
|
"id": "byName",
|
|
"options": "Nivel de log"
|
|
},
|
|
"properties": [
|
|
{
|
|
"id": "custom.width",
|
|
"value": 115
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"gridPos": {
|
|
"h": 22,
|
|
"w": 22,
|
|
"x": 0,
|
|
"y": 0
|
|
},
|
|
"id": 1,
|
|
"options": {
|
|
"cellHeight": "sm",
|
|
"footer": {
|
|
"countRows": false,
|
|
"fields": "",
|
|
"reducer": [
|
|
"sum"
|
|
],
|
|
"show": false
|
|
},
|
|
"showHeader": true,
|
|
"sortBy": []
|
|
},
|
|
"pluginVersion": "11.6.3",
|
|
"targets": [
|
|
{
|
|
"alias": "",
|
|
"bucketAggs": [
|
|
{
|
|
"field": "@timestamp",
|
|
"id": "2",
|
|
"settings": {
|
|
"interval": "auto"
|
|
},
|
|
"type": "date_histogram"
|
|
}
|
|
],
|
|
"datasource": {
|
|
"type": "grafana-opensearch-datasource",
|
|
"uid": "${DS_OPENSEARCH}"
|
|
},
|
|
"format": "table",
|
|
"luceneQueryType": "Logs",
|
|
"metrics": [
|
|
{
|
|
"id": "1",
|
|
"type": "logs"
|
|
}
|
|
],
|
|
"query": "syslog.identifier:\"ogcore\" AND (parsed_message.severity:\"INFO\" OR parsed_message.severity:\"WARNING\" OR parsed_message.severity:\"ERROR\")",
|
|
"queryType": "lucene",
|
|
"refId": "A",
|
|
"timeField": "@timestamp"
|
|
}
|
|
],
|
|
"title": "Panel Title",
|
|
"transformations": [
|
|
{
|
|
"id": "organize",
|
|
"options": {
|
|
"excludeByName": {
|
|
"_id": true,
|
|
"_index": true,
|
|
"_source": true,
|
|
"_type": true,
|
|
"agent.ephemeral_id": true,
|
|
"agent.hostname": true,
|
|
"agent.id": true,
|
|
"agent.name": true,
|
|
"agent.type": true,
|
|
"agent.version": true,
|
|
"data_decoded.agent_version": true,
|
|
"data_decoded.cfg": true,
|
|
"data_decoded.exe": true,
|
|
"data_decoded.ida": true,
|
|
"data_decoded.idc": true,
|
|
"data_decoded.ido": true,
|
|
"data_decoded.iph": true,
|
|
"data_decoded.job_id": true,
|
|
"data_decoded.nfl": true,
|
|
"data_decoded.npc": true,
|
|
"data_decoded.progress": true,
|
|
"data_decoded.secret": true,
|
|
"data_decoded.timestamp": true,
|
|
"data_decoded.tpc": true,
|
|
"data_json": true,
|
|
"debug": true,
|
|
"ecs.version": true,
|
|
"event.created": true,
|
|
"event.kind": true,
|
|
"host.architecture": true,
|
|
"host.containerized": true,
|
|
"host.hostname": true,
|
|
"host.id": true,
|
|
"host.ip": true,
|
|
"host.mac": true,
|
|
"host.name": true,
|
|
"host.os.codename": true,
|
|
"host.os.family": true,
|
|
"host.os.kernel": true,
|
|
"host.os.name": true,
|
|
"host.os.platform": true,
|
|
"host.os.type": true,
|
|
"host.os.version": true,
|
|
"input.type": true,
|
|
"journald.audit.login_uid": true,
|
|
"journald.audit.session": true,
|
|
"journald.custom.runtime_scope": true,
|
|
"journald.custom.selinux_context": true,
|
|
"journald.custom.syslog_raw": true,
|
|
"journald.custom.syslog_timestamp": true,
|
|
"journald.gid": true,
|
|
"journald.host.boot_id": true,
|
|
"journald.pid": true,
|
|
"journald.process.capabilites": true,
|
|
"journald.process.command_line": true,
|
|
"journald.process.executable": true,
|
|
"journald.process.name": true,
|
|
"journald.uid": true,
|
|
"log.file.path": true,
|
|
"log.offset": true,
|
|
"log.syslog.facility.name": true,
|
|
"log.syslog.priority": true,
|
|
"message": true,
|
|
"message_decoded.function": true,
|
|
"message_decoded.in_oglive": true,
|
|
"message_decoded.message": false,
|
|
"message_decoded.threadName": true,
|
|
"message_decoded.timestamp": true,
|
|
"message_raw": true,
|
|
"parsed_message": true,
|
|
"parsed_message.component": true,
|
|
"parsed_message.datetime": true,
|
|
"parsed_message.desc": false,
|
|
"parsed_message.operation": true,
|
|
"parsed_message.params": true,
|
|
"parsed_message.params.cache-adapter": true,
|
|
"parsed_message.params.exception": true,
|
|
"parsed_message.params.iph": true,
|
|
"parsed_message.params.key": true,
|
|
"parsed_message.params.method": true,
|
|
"parsed_message.params.request_uri": true,
|
|
"parsed_message.params.route": true,
|
|
"parsed_message.params.route_parameters._controller": true,
|
|
"parsed_message.params.route_parameters._route": true,
|
|
"parsed_message.params.timestamp": true,
|
|
"parsed_message.severity": false,
|
|
"process.args": true,
|
|
"process.args_count": true,
|
|
"process.command_line": true,
|
|
"process.pid": true,
|
|
"syslog.facility": true,
|
|
"syslog.identifier": true,
|
|
"syslog.pid": true,
|
|
"syslog.priority": true,
|
|
"systemd.cgroup": true,
|
|
"systemd.invocation_id": true,
|
|
"systemd.slice": true,
|
|
"systemd.transport": true,
|
|
"systemd.unit": true,
|
|
"user.group.id": true,
|
|
"user.id": true
|
|
},
|
|
"includeByName": {},
|
|
"indexByName": {
|
|
"@timestamp": 0,
|
|
"_id": 1,
|
|
"_index": 2,
|
|
"_source": 3,
|
|
"_type": 4,
|
|
"agent.ephemeral_id": 5,
|
|
"agent.hostname": 6,
|
|
"agent.id": 7,
|
|
"agent.name": 8,
|
|
"agent.type": 9,
|
|
"agent.version": 10,
|
|
"debug": 16,
|
|
"ecs.version": 11,
|
|
"event.created": 17,
|
|
"event.kind": 18,
|
|
"host.hostname": 12,
|
|
"host.id": 13,
|
|
"host.name": 14,
|
|
"journald.audit.login_uid": 19,
|
|
"journald.audit.session": 20,
|
|
"journald.custom.runtime_scope": 21,
|
|
"journald.custom.selinux_context": 22,
|
|
"journald.custom.syslog_timestamp": 23,
|
|
"journald.gid": 24,
|
|
"journald.host.boot_id": 25,
|
|
"journald.pid": 26,
|
|
"journald.process.capabilites": 27,
|
|
"journald.process.command_line": 28,
|
|
"journald.process.executable": 29,
|
|
"journald.process.name": 30,
|
|
"journald.uid": 31,
|
|
"log.syslog.facility.name": 32,
|
|
"log.syslog.priority": 33,
|
|
"message": 15,
|
|
"parsed_message.component": 34,
|
|
"parsed_message.datetime": 35,
|
|
"parsed_message.desc": 38,
|
|
"parsed_message.operation": 37,
|
|
"parsed_message.params": 39,
|
|
"parsed_message.params.cache-adapter": 40,
|
|
"parsed_message.params.exception": 41,
|
|
"parsed_message.params.iph": 42,
|
|
"parsed_message.params.key": 43,
|
|
"parsed_message.params.method": 44,
|
|
"parsed_message.params.request_uri": 45,
|
|
"parsed_message.params.route": 46,
|
|
"parsed_message.params.route_parameters._controller": 47,
|
|
"parsed_message.params.route_parameters._route": 48,
|
|
"parsed_message.params.timestamp": 49,
|
|
"parsed_message.severity": 36,
|
|
"process.args": 50,
|
|
"process.args_count": 51,
|
|
"process.command_line": 52,
|
|
"process.pid": 53,
|
|
"syslog.facility": 54,
|
|
"syslog.identifier": 55,
|
|
"syslog.pid": 56,
|
|
"syslog.priority": 57,
|
|
"systemd.cgroup": 58,
|
|
"systemd.invocation_id": 59,
|
|
"systemd.slice": 60,
|
|
"systemd.transport": 61,
|
|
"systemd.unit": 62,
|
|
"user.group.id": 63,
|
|
"user.id": 64
|
|
},
|
|
"renameByName": {
|
|
"@timestamp": "Fecha",
|
|
"agent.type": "",
|
|
"message_decoded.message": "message",
|
|
"message_decoded.severity": "log level",
|
|
"parsed_message.desc": "Descripción",
|
|
"parsed_message.operation": "",
|
|
"parsed_message.severity": "Nivel de log"
|
|
}
|
|
}
|
|
}
|
|
],
|
|
"type": "table"
|
|
}
|
|
],
|
|
"schemaVersion": 41,
|
|
"tags": [],
|
|
"templating": {
|
|
"list": []
|
|
},
|
|
"time": {
|
|
"from": "now-5m",
|
|
"to": "now"
|
|
},
|
|
"timepicker": {},
|
|
"timezone": "browser",
|
|
"title": "ogcore-logs",
|
|
"uid": "ogcore-logs",
|
|
"version": 4,
|
|
"weekStart": ""
|
|
} |