Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update kubernetes templates for elastic-agent [templates.d] #6406

Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
100 changes: 50 additions & 50 deletions deploy/kubernetes/elastic-agent-standalone/templates.d/apache.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,54 @@
inputs:
- name: filestream-apache
id: filestream-apache-${kubernetes.hints.container_id}
type: filestream
use_output: default
streams:
- condition: ${kubernetes.hints.apache.access.enabled} == true or ${kubernetes.hints.apache.enabled} == true
data_stream:
dataset: apache.access
type: logs
exclude_files:
- .gz$
file_identity:
fingerprint: null
parsers:
- container:
format: auto
stream: ${kubernetes.hints.apache.access.stream|'all'}
paths:
- /var/log/containers/*${kubernetes.hints.container_id}.log
prospector:
scanner:
fingerprint:
enabled: true
symlinks: true
tags:
- apache-access
- condition: ${kubernetes.hints.apache.error.enabled} == true or ${kubernetes.hints.apache.enabled} == true
data_stream:
dataset: apache.error
type: logs
exclude_files:
- .gz$
file_identity:
fingerprint: null
parsers:
- container:
format: auto
stream: ${kubernetes.hints.apache.error.stream|'all'}
paths:
- /var/log/containers/*${kubernetes.hints.container_id}.log
processors:
- add_locale: null
prospector:
scanner:
fingerprint:
enabled: true
symlinks: true
tags:
- apache-error
data_stream.namespace: default
- name: httpjson-apache
id: httpjson-apache-${kubernetes.hints.container_id}
type: httpjson
Expand Down Expand Up @@ -97,53 +147,3 @@ inputs:
period: ${kubernetes.hints.apache.status.period|kubernetes.hints.apache.period|'30s'}
server_status_path: /server-status
data_stream.namespace: default
- name: filestream-apache
id: filestream-apache-${kubernetes.hints.container_id}
type: filestream
use_output: default
streams:
- condition: ${kubernetes.hints.apache.access.enabled} == true or ${kubernetes.hints.apache.enabled} == true
data_stream:
dataset: apache.access
type: logs
exclude_files:
- .gz$
file_identity:
fingerprint: null
parsers:
- container:
format: auto
stream: ${kubernetes.hints.apache.access.stream|'all'}
paths:
- /var/log/containers/*${kubernetes.hints.container_id}.log
prospector:
scanner:
fingerprint:
enabled: true
symlinks: true
tags:
- apache-access
- condition: ${kubernetes.hints.apache.error.enabled} == true or ${kubernetes.hints.apache.enabled} == true
data_stream:
dataset: apache.error
type: logs
exclude_files:
- .gz$
file_identity:
fingerprint: null
parsers:
- container:
format: auto
stream: ${kubernetes.hints.apache.error.stream|'all'}
paths:
- /var/log/containers/*${kubernetes.hints.container_id}.log
processors:
- add_locale: null
prospector:
scanner:
fingerprint:
enabled: true
symlinks: true
tags:
- apache-error
data_stream.namespace: default
42 changes: 21 additions & 21 deletions deploy/kubernetes/elastic-agent-standalone/templates.d/cef.yml
Original file line number Diff line number Diff line change
@@ -1,25 +1,4 @@
inputs:
- name: tcp-cef
id: tcp-cef-${kubernetes.hints.container_id}
type: tcp
use_output: default
streams:
- condition: ${kubernetes.hints.cef.log.enabled} == true or ${kubernetes.hints.cef.enabled} == true
data_stream:
dataset: cef.log
type: logs
host: localhost:9004
processors:
- rename:
fields:
- from: message
to: event.original
- decode_cef:
field: event.original
tags:
- cef
- forwarded
data_stream.namespace: default
- name: filestream-cef
id: filestream-cef-${kubernetes.hints.container_id}
type: filestream
Expand Down Expand Up @@ -76,3 +55,24 @@ inputs:
- cef
- forwarded
data_stream.namespace: default
- name: tcp-cef
id: tcp-cef-${kubernetes.hints.container_id}
type: tcp
use_output: default
streams:
- condition: ${kubernetes.hints.cef.log.enabled} == true or ${kubernetes.hints.cef.enabled} == true
data_stream:
dataset: cef.log
type: logs
host: localhost:9004
processors:
- rename:
fields:
- from: message
to: event.original
- decode_cef:
field: event.original
tags:
- cef
- forwarded
data_stream.namespace: default
Original file line number Diff line number Diff line change
@@ -1,33 +1,4 @@
inputs:
- name: filestream-fireeye
id: filestream-fireeye-${kubernetes.hints.container_id}
type: filestream
use_output: default
streams:
- condition: ${kubernetes.hints.fireeye.nx.enabled} == true or ${kubernetes.hints.fireeye.enabled} == true
data_stream:
dataset: fireeye.nx
type: logs
exclude_files:
- .gz$
file_identity:
fingerprint: null
parsers:
- container:
format: auto
stream: ${kubernetes.hints.fireeye.nx.stream|'all'}
paths:
- /var/log/containers/*${kubernetes.hints.container_id}.log
processors:
- add_locale: null
prospector:
scanner:
fingerprint:
enabled: true
symlinks: true
tags:
- fireeye-nx
data_stream.namespace: default
- name: udp-fireeye
id: udp-fireeye-${kubernetes.hints.container_id}
type: udp
Expand Down Expand Up @@ -64,3 +35,32 @@ inputs:
- forwarded
tcp: null
data_stream.namespace: default
- name: filestream-fireeye
id: filestream-fireeye-${kubernetes.hints.container_id}
type: filestream
use_output: default
streams:
- condition: ${kubernetes.hints.fireeye.nx.enabled} == true or ${kubernetes.hints.fireeye.enabled} == true
data_stream:
dataset: fireeye.nx
type: logs
exclude_files:
- .gz$
file_identity:
fingerprint: null
parsers:
- container:
format: auto
stream: ${kubernetes.hints.fireeye.nx.stream|'all'}
paths:
- /var/log/containers/*${kubernetes.hints.container_id}.log
processors:
- add_locale: null
prospector:
scanner:
fingerprint:
enabled: true
symlinks: true
tags:
- fireeye-nx
data_stream.namespace: default
Original file line number Diff line number Diff line change
@@ -1,4 +1,32 @@
inputs:
- name: haproxy/metrics-haproxy
id: haproxy/metrics-haproxy-${kubernetes.hints.container_id}
type: haproxy/metrics
use_output: default
streams:
- condition: ${kubernetes.hints.haproxy.info.enabled} == true or ${kubernetes.hints.haproxy.enabled} == true
data_stream:
dataset: haproxy.info
type: metrics
hosts:
- ${kubernetes.hints.haproxy.info.host|kubernetes.hints.haproxy.host|'tcp://127.0.0.1:14567'}
metricsets:
- info
password: ${kubernetes.hints.haproxy.info.password|kubernetes.hints.haproxy.password|'admin'}
period: ${kubernetes.hints.haproxy.info.period|kubernetes.hints.haproxy.period|'10s'}
username: ${kubernetes.hints.haproxy.info.username|kubernetes.hints.haproxy.username|'admin'}
- condition: ${kubernetes.hints.haproxy.stat.enabled} == true or ${kubernetes.hints.haproxy.enabled} == true
data_stream:
dataset: haproxy.stat
type: metrics
hosts:
- ${kubernetes.hints.haproxy.stat.host|kubernetes.hints.haproxy.host|'tcp://127.0.0.1:14567'}
metricsets:
- stat
password: ${kubernetes.hints.haproxy.stat.password|kubernetes.hints.haproxy.password|'admin'}
period: ${kubernetes.hints.haproxy.stat.period|kubernetes.hints.haproxy.period|'10s'}
username: ${kubernetes.hints.haproxy.stat.username|kubernetes.hints.haproxy.username|'admin'}
data_stream.namespace: default
- name: filestream-haproxy
id: filestream-haproxy-${kubernetes.hints.container_id}
type: filestream
Expand Down Expand Up @@ -45,31 +73,3 @@ inputs:
- forwarded
- haproxy-log
data_stream.namespace: default
- name: haproxy/metrics-haproxy
id: haproxy/metrics-haproxy-${kubernetes.hints.container_id}
type: haproxy/metrics
use_output: default
streams:
- condition: ${kubernetes.hints.haproxy.info.enabled} == true or ${kubernetes.hints.haproxy.enabled} == true
data_stream:
dataset: haproxy.info
type: metrics
hosts:
- ${kubernetes.hints.haproxy.info.host|kubernetes.hints.haproxy.host|'tcp://127.0.0.1:14567'}
metricsets:
- info
password: ${kubernetes.hints.haproxy.info.password|kubernetes.hints.haproxy.password|'admin'}
period: ${kubernetes.hints.haproxy.info.period|kubernetes.hints.haproxy.period|'10s'}
username: ${kubernetes.hints.haproxy.info.username|kubernetes.hints.haproxy.username|'admin'}
- condition: ${kubernetes.hints.haproxy.stat.enabled} == true or ${kubernetes.hints.haproxy.enabled} == true
data_stream:
dataset: haproxy.stat
type: metrics
hosts:
- ${kubernetes.hints.haproxy.stat.host|kubernetes.hints.haproxy.host|'tcp://127.0.0.1:14567'}
metricsets:
- stat
password: ${kubernetes.hints.haproxy.stat.password|kubernetes.hints.haproxy.password|'admin'}
period: ${kubernetes.hints.haproxy.stat.period|kubernetes.hints.haproxy.period|'10s'}
username: ${kubernetes.hints.haproxy.stat.username|kubernetes.hints.haproxy.username|'admin'}
data_stream.namespace: default
54 changes: 27 additions & 27 deletions deploy/kubernetes/elastic-agent-standalone/templates.d/iis.yml
Original file line number Diff line number Diff line change
@@ -1,31 +1,4 @@
inputs:
- name: iis/metrics-iis
id: iis/metrics-iis-${kubernetes.hints.container_id}
type: iis/metrics
use_output: default
streams:
- condition: ${kubernetes.hints.iis.application_pool.enabled} == true or ${kubernetes.hints.iis.enabled} == true
data_stream:
dataset: iis.application_pool
type: metrics
metricsets:
- application_pool
period: ${kubernetes.hints.iis.application_pool.period|kubernetes.hints.iis.period|'10s'}
- condition: ${kubernetes.hints.iis.webserver.enabled} == true or ${kubernetes.hints.iis.enabled} == true
data_stream:
dataset: iis.webserver
type: metrics
metricsets:
- webserver
period: ${kubernetes.hints.iis.webserver.period|kubernetes.hints.iis.period|'10s'}
- condition: ${kubernetes.hints.iis.website.enabled} == true or ${kubernetes.hints.iis.enabled} == true
data_stream:
dataset: iis.website
type: metrics
metricsets:
- website
period: ${kubernetes.hints.iis.website.period|kubernetes.hints.iis.period|'10s'}
data_stream.namespace: default
- name: filestream-iis
id: filestream-iis-${kubernetes.hints.container_id}
type: filestream
Expand Down Expand Up @@ -80,3 +53,30 @@ inputs:
tags:
- iis-error
data_stream.namespace: default
- name: iis/metrics-iis
id: iis/metrics-iis-${kubernetes.hints.container_id}
type: iis/metrics
use_output: default
streams:
- condition: ${kubernetes.hints.iis.application_pool.enabled} == true or ${kubernetes.hints.iis.enabled} == true
data_stream:
dataset: iis.application_pool
type: metrics
metricsets:
- application_pool
period: ${kubernetes.hints.iis.application_pool.period|kubernetes.hints.iis.period|'10s'}
- condition: ${kubernetes.hints.iis.webserver.enabled} == true or ${kubernetes.hints.iis.enabled} == true
data_stream:
dataset: iis.webserver
type: metrics
metricsets:
- webserver
period: ${kubernetes.hints.iis.webserver.period|kubernetes.hints.iis.period|'10s'}
- condition: ${kubernetes.hints.iis.website.enabled} == true or ${kubernetes.hints.iis.enabled} == true
data_stream:
dataset: iis.website
type: metrics
metricsets:
- website
period: ${kubernetes.hints.iis.website.period|kubernetes.hints.iis.period|'10s'}
data_stream.namespace: default
Loading
Loading