Hi,
for our inputs.conf. I need to move mongo, apache and others to a new index called common and mongo. Does the following looks good ?. Can I do any more optimizations?.
Thanks for all the support.
[monitor:///var/log/mongo/...]
crcSalt =
disabled = false
index = mongo
[monitor:///var/log/hpp/…]
crcSalt =
disabled = false
index = common
[monitor:///var/log/apache2/...]
crcSalt =
disabled = false
index = common
[monitor:///var/log/epp/…]
crcSalt =
disabled = false
index = common
[monitor:///var/log/prd/deployment/...]
crcSalt =
disabled = false
index = common
[monitor:///var/log/prd/…]
crcSalt =
disabled = false
index = elastica
{% if 'gr’ in salt['grains.get']('roles') %}blacklist = /var/log/prd/gr/png|\.(gz|bz2|z|zip|\d)|UNKNOWN.INFO|audit\.log$
{% else %}blacklist = \.(gz|bz2|z|zip|\d)|UNKNOWN.INFO|audit\.log$
{% endif %}
[monitor:///var/log/...]
crcSalt =
disabled = false
index = main
blacklist = \.(gz|bz2|z|zip|\d)|UNKNOWN.INFO|prd|apache2|mongo|hpp|epp|audit\.log$
↧