Splunkãã¤ã³ã¹ãã¼ã«ãã¦è©¦ç¨ãã¦ã¿ãã®ã§ãã¾ã¨ãã¦ããã¾ãã Splunkã¨ã¯ ãããããã¼ã¿ã«ã¤ã³ããã¯ã¹ãã¤ãã¦æ¤ç´¢/åæããããããããã®ã½ããã¦ã§ã¢ã§ãã 詳ããã¯ä¸è¨ãåç §ãã ããã Splunkæ¥æ¬èªå ¬å¼ãµã¤ã ä»å対象ã®ãã¼ã¿ã¯Network Deviceã®syslogã§ãã 試ç¨ãããã¨æã£ããã£ããã¯ä¸è¨ã®2ã¤ã ã»é害æãåé¡ç¹å®ã¸ã®æéç縮ã ã»äººãé¸ã°ãã誰ã§ããã°ãç°¡åã«é²è¦§åºæ¥ãããã«ã ãªã«ã¯ã¨ãããsyslogãµã¼ããGUIåããããã£ãã®ã§ãã£ã¦ã¿ã¾ããã æ§æå³ Network Deviceãsyslogãµã¼ãã«ãã°ãéä¿¡ãèç©ãã¦ãã¾ãã syslogãµã¼ãããSplunkãµã¼ãã¸UniversalForwarderã使ç¨ãã¦ãã°ã転éãã¦ãã¾ãã syslogãµã¼ãã«Splunkãã¤ã³ã¹ãã¼ã«ãã¦1å°ã§å®çµåºæ¥ãã®ã§ããã ä»åã¯èç©ãµã¼ãã¨é²
ãããããã°ãåéãã æ¨å¹´ãããããfluentdã¨ããååãããè³ã«ããããã«ãªãã¾ãããå¼ç¤¾ã§ã®å®éã®ããã¸ã§ã¯ãæ´»ç¨ãåºã¦ãã¦ãã¾ããããã§ä»åã¯åå¿é²ã¨ãã¦ã»ããã¢ãããããã©ã°ã¤ã³ã®ã¤ã³ã¹ãã¼ã«çã®åºæ¬çãªæé ãç´¹ä»ãããã¨æãã¾ãã ã»ããã¢ãã Amazon Linuxã«ã¤ã³ã¹ãã¼ã«ããããã«ãªãã¸ããªãè¨å®ãã¦ç°¡åã¤ã³ã¹ãã¼ã«ãã¾ãã $ sudo vi /etc/yum.repos.d/td.repo [treasuredata] name=TreasureData baseurl=http://packages.treasure-data.com/redhat/$basearch gpgcheck=0 yumã§ã¤ã³ã¹ãã¼ã«ã«ã¦èªåèµ·åè¨å®ãã¾ãã $ sudo yum install td-agent -y $ sudo service td-agent start
indexã¯Elasticsearchã«ãããã¹ãã¼ãã¿ãããªãã®ãªããã§ããã logstashå½¢å¼ï¼LogStashã¯javaã®ãã°importæ©æ§ï¼ï¼ã«ããå ´åã indexã¯importããæ¥æ¯ã«ä½æããã¾ãã ä¾ãã°ä»æ¥ãã5æ¥éFluentdã§åå¾ãç¶ããå ´åã logstash-2013.09.11 logstash-2013.09.12 logstash-2013.09.13 logstash-2013.09.14 logstash-2013.09.15 ã¿ããã«indexã1æ¥æ¯ã«åããã¦ä½æããã¾ããããã®å©ç¹ã¯ ã»ãã¼ã¿æ¤ç´¢ããæã«æ¥ä»ã§ç¯å²æå®ããã¨å¯¾è±¡ãã¼ã¿ãçµããã®ã§æ¤ç´¢ãæ©ããªã ã»ããç¨åº¦çµéãããã¼ã¿ãæ¥ä»ã§ç®¡çãã¦åé¤ãããã§ãããã¤ã¾ããã°ãã¼ãã¼ãæ©æ§ å¶ç¶ãRebuild.fmã§èãã¦ã¹ã²ã¼ã¨æãã¾ããã ãã¼ã¿ç®¡çã¾ã§èãããã¦ããªãã§è³ããå°½ã
ããã«ã¡ã¯ï¼ oko_changã§ãã ãã§ã«è²ã ãªæ¹ãã¾ã¨ãã¦ãã¾ããããã£ã±ãèªåãªãã«ããã°ã«ã¾ã¨ããã»ããè¦ããããã®ã§ä»åã¯fluentdã«ã¤ãã¦æ¸ãã¾ãã Fluentdã¨ã¯ï¼ ãã¡ããè¦ãã®ããã¯ãæ©ãã§ãããã ç°å¢ ã©ã¡ããCentOS 6.5ã使ç¨ãã¦ãã¾ãã ä»åã¯Fluentdã使ã£ã¦ãã¼ã«ã«ã®ãã¡ã¤ã«ã«ä¿åãã¤ã¤ã転éå ã«ãä¿åããã¾ã§ç¢ºèªãã¾ãã 転éå ç°å¢ ã¤ã³ã¹ãã¼ã«å Fluentdã«ã¤ãã¦ã¯è²ã ãªæ¹ãããã°ã¨ãã§ãã¾ã¨ãã¦ããã®ã§ããã¡ããåèã«ãªãã¾ãããå ¬å¼ããã¥ã¡ã³ããã¨ã¦ãå å®ãã¦ãã¾ããã ããã«Fluentdãã¤ã³ã¹ãã¼ã«åã«ããã¹ãäºãè¨è¼ããã¦ãã¾ãã®ã§ãè¨å®ãã¾ãã â»limits.confã¨sysctl.confã«ãããã追è¨ãã # vi /etc/security/limits.conf root soft nofile 65536
ã´ã¯ãã®å¤§å¹³ã§ãã ç§ã«ã¨ã£ã¦ä¸çªå¤§äºã§æ¿ãã®å¹ããªããã¥ã¼ã¸ã·ã£ã³ã¯ãã ã¾ããããã§ãããç§ã«ã¨ã£ã¦ã¯ã©ã¦ãã³ã³ãã¥ã¼ãã£ã³ã°ã®ãµã¼ãã¹ã®ä¸ã§ä¸çªå¤§äºã§æ¿ããå¹ããªããµã¼ãã¹ã¯S3ã§ãã å¤ç¨®å¤æ§ãªAPIãç¨ãã¦æè»ã«ãã¡ã¤ã«ã®æä½ãåºæ¥ãäºããâ99.999999999ï¼ âã¨è¬³ããã¦ããé«ãèé害æ§ãS3ã«ãããã¼ã¿ãElastic MapReduceãRedshiftãªã©ãç¨ãã¦æ軽ã«ãã¼ã¿è§£æãè¡ããåºç¤ãæä¾ããã¦ãããã¨ãªã©ããã¾ãã«ä¾¿å©ããã¦S3ã®ä»£æ¿ã¨ãªããµã¼ãã¹ãæ¢ãã ãã®ãé£ããç¶æ ã§ãã ãã¡ããå¤ãã®AWSã¦ã¼ã¶ã¼ãåãããã«S3ã®ä¾¿å©ãã享åãã¦ããã¨æãã¾ãããã¤ã³ã¿ã¼ãããä¸ã§ãå¤ãã®ããã°çã§ãã®é åãèªããã¦ãã¾ãããã®ä¸ã§æ¬è¨äºã¯æ¢ã«åå¨ããè¨äºã¨ä¼¼ããããªå 容ãæ¸ãã¦ãã¾ãããããã¾ããããå¼ç¤¾ãªãã®S3ã®ä½¿ãæ¹ã«ã¤ãã¦ãç´¹ä»ãããã¨æãã¾ãã ãªã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}