Skip to content

[VMware] Add more vSphere/ESXi logs - #8122

Merged
philippkahr merged 37 commits into
elastic:mainfrom
philippkahr:vmware-vsphere-grok
Dec 14, 2023
Merged

philippkahr merged 37 commits into
elastic:mainfrom
philippkahr:vmware-vsphere-grok

Conversation

@philippkahr

@philippkahr philippkahr commented Oct 6, 2023 •

Copy link
Copy Markdown
Contributor

Hi,

multiple things:

  • Added a bunch more log lines to test. not only vcenter/vsphere also ESXI host related.
  • Adapted the original GROK parser to not drop events, instead just store them. This should be more in line with what we want to achieve with logs+.
  • Added parsing for login, logout events.
  • Added syslog parsing scripts from Arista
  • Added support for the user agent parser
  • Bumped the ECS version to 8.10.0
  • Parsing DNS events into appropriate DNS fields.
  • Parse the ESXI SSH login and logout message

Since this is a bit more of a change. i am not sure that 1.9.0 is enough of a version bump, or if we want to go 2.0.0

  • See if it's possible to differentiate between ESXI and vsphere logs for event.dataset or something like this. I don't want to introduce a new datastream with: logs-vsphere_esxi.log. Don't think that this is needed.

  • figure out how to deal with multiline. It's not a JSON, not real KV as well. Bit weird to parse. Maybe try to parse only important stuff such as eventTypeId to ECS.

<166>1 2023-09-18T16:07:55.298Z esxihost Hostd: info hostd[67566312] [Originator@1244 sub=Hostsvc.VmkVprobSource] VmkVprobSource::Post event: (vim.event.EventEx) {
<166>1 2023-09-18T16:07:55.298Z esxihost Hostd: -->    key = 161,
<166>1 2023-09-18T16:07:55.298Z esxihost Hostd: -->    chainId = -897703048,
<166>1 2023-09-18T16:07:55.298Z esxihost Hostd: -->    createdTime = "1970-01-01T00:00:00Z",
<166>1 2023-09-18T16:07:55.298Z esxihost Hostd: -->    userName = "",
<166>1 2023-09-18T16:07:55.298Z esxihost Hostd: -->    host = (vim.event.HostEventArgument) {
<166>1 2023-09-18T16:07:55.298Z esxihost Hostd: -->       name = "esxihost",
<166>1 2023-09-18T16:07:55.298Z esxihost Hostd: -->       host = 'vim.HostSystem:ha-host'
<166>1 2023-09-18T16:07:55.298Z esxihost Hostd: -->    },
<166>1 2023-09-18T16:07:55.298Z esxihost Hostd: -->    eventTypeId = "esx.problem.vmsyslogd.remote.failure",
<166>1 2023-09-18T16:07:55.298Z esxihost Hostd: -->    arguments = (vmodl.KeyAnyValue) [
<166>1 2023-09-18T16:07:55.298Z esxihost Hostd: -->       (vmodl.KeyAnyValue) {
<166>1 2023-09-18T16:07:55.298Z esxihost Hostd: -->          key = "1",
<166>1 2023-09-18T16:07:55.298Z esxihost Hostd: -->          value = "192.168.1.1:1234"
<166>1 2023-09-18T16:07:55.298Z esxihost Hostd: -->       }
<166>1 2023-09-18T16:07:55.298Z esxihost Hostd: -->    ],
<166>1 2023-09-18T16:07:55.298Z esxihost Hostd: -->    objectId = "ha-host",
<166>1 2023-09-18T16:07:55.298Z esxihost Hostd: -->    objectType = "vim.HostSystem",
<166>1 2023-09-18T16:07:55.298Z esxihost Hostd: --> }

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.

@philippkahr philippkahr added enhancement New feature or request bugfix Pull request that fixes a bug issue labels Oct 6, 2023
@philippkahr
philippkahr requested a review from a team as a code owner October 6, 2023 15:51
@elasticmachine

elasticmachine commented Oct 6, 2023 •

Copy link
Copy Markdown

💚 Build Succeeded

the below badges are clickable and redirect to their specific view in the CI or DOCS
Pipeline View Test View Changes Artifacts preview preview

Expand to view the summary

Build stats

  • Start Time: 2023-12-14T14:32:06.352+0000

  • Duration: 22 min 30 sec

Test stats 🧪

Test Results
Failed 0
Passed 17
Skipped 0
Total 17

🤖 GitHub comments

Expand to view the GitHub comments

To re-run your PR in the CI, just comment with:

  • /test : Re-trigger the build.

@elasticmachine

elasticmachine commented Oct 6, 2023 •

Copy link
Copy Markdown

🌐 Coverage report

Name Metrics % (covered/total) Diff
Packages 100.0% (1/1) 💚
Files 100.0% (4/4) 💚
Classes 100.0% (4/4) 💚
Methods 100.0% (37/37) 💚
Lines 94.521% (276/292) ❕
Conditionals 100.0% (0/0) 💚

@philippkahr

Copy link
Copy Markdown
Contributor Author

/test

@philippkahr
philippkahr requested a review from a team as a code owner November 3, 2023 14:24
@philippkahr

Copy link
Copy Markdown
Contributor Author

FYI I am on PTO from 4th November till 20th november.

Comment thread packages/vsphere/data_stream/log/elasticsearch/ingest_pipeline/default.yml Outdated
@ishleenk17

Copy link
Copy Markdown
Member

@philippkahr : There are some files for infoblox Integration. Was that added by mistake ?

Comment thread packages/vsphere/manifest.yml Outdated
@elasticmachine

Copy link
Copy Markdown

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

Comment thread packages/vsphere/changelog.yml Outdated
@devamanv

devamanv commented Dec 12, 2023 •

Copy link
Copy Markdown
Contributor

@philippkahr I see that are still some unanswered review comments that were marked resolved without any action or comment on them. Can you please revisit or address those? This will help us close the review on this PR and approve the changes faster. Thanks

Co-authored-by: Aman <38116245+devamanv@users.noreply.github.com>
@philippkahr

philippkahr commented Dec 12, 2023 •

Copy link
Copy Markdown
Contributor Author

@devamanv I don't see any comments that I didn't address, can you point me to them please? I think I get it now, all my comments had a pending tag. I had to go to files and submit my own review 😵‍💫

Screenshot 2023-12-12 at 21 58 27

Comment thread packages/vsphere/changelog.yml Outdated
Co-authored-by: muthu-mps <101238137+muthu-mps@users.noreply.github.com>
@devamanv

devamanv commented Dec 13, 2023 •

Copy link
Copy Markdown
Contributor

@devamanv I don't see any comments that I didn't address, can you point me to them please? I think I get it now, all my comments had a pending tag. I had to go to files and submit my own review 😵‍💫

That's fine, just wanted to make sure we were tracking the progress on this one. The changes look good. I will review the changes again once all the CI checks have passed and complete my part of the review. Thanks for addressing the review comments.

@philippkahr

Copy link
Copy Markdown
Contributor Author

@devamanv can you check the buildkite?


failed to solve: process "/bin/sh -c go get -u github.com/vmware/govmomi/vcsim@v0.25.0" did not complete successfully: exit code: 2
--
  | Error: error running package system tests: could not complete test run: could not setup service: could not boot up service using Docker Compose: running Docker Compose up command failed: exit status 17


I don't think that's on me. Since I didn't touch the govmomi go stuff.

@devamanv

Copy link
Copy Markdown
Contributor

@philippkahr I have a hunch. Could you try to change the Go version to 1.17 in this file packages/vsphere/_dev/deploy/docker/docker-compose.yml and see if it fixes the issue? If it does, will try to explain the potential cause of this.

@devamanv

devamanv commented Dec 14, 2023 •

Copy link
Copy Markdown
Contributor

So, a plausible explanation of what could have caused the checks to fail is as follows:
I tried downloading the package that is failing in the CI and noticed that it's trying to download the package google/uuid v1.5.0

> go get -u -v github.com/vmware/govmomi/vcsim@v0.25.0
go: downloading github.com/vmware/govmomi v0.25.0
go: downloading github.com/google/uuid v0.0.0-20170306145142-6a5e28554805
go: downloading github.com/google/uuid v1.5.0

This in turn threw the following error:

timeNow().UnixMilli undefined (type time.Time has no field or method UnixMilli)

Note that I was able to see this error by adding the -v flag

The uuid package recently added this change to support v7 of UUID. Finally, this implementation uses time.UnixMilli function, which was introduced in Go v1.17. So, the only option to fix this error was to upgrade the Go version.

@devamanv

devamanv commented Dec 14, 2023 •

Copy link
Copy Markdown
Contributor

@philippkahr Now that we have updated the Go version, we might as well make another change to the dockerfile to replace the go get with go install.
From the official documentation:

Starting with Go 1.17, installing executables with go get is deprecated. go install may be used instead.

A similar change was done here in the vSphere module.

@devamanv devamanv changed the title [VMWARE] vsphere logs [VMware] vSphere logs Dec 14, 2023
@devamanv devamanv changed the title [VMware] vSphere logs [VMware] Add more vSphere/ESXi logs Dec 14, 2023
Comment thread packages/vsphere/_dev/deploy/docker/Dockerfile Outdated
philippkahr and others added 2 commits December 14, 2023 13:36
Co-authored-by: Aman <38116245+devamanv@users.noreply.github.com>
@muthu-mps

Copy link
Copy Markdown
Contributor

/test

@devamanv devamanv left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@philippkahr
philippkahr merged commit 4ccf4b9 into elastic:main Dec 14, 2023
@philippkahr
philippkahr deleted the vmware-vsphere-grok branch December 14, 2023 15:12
@elasticmachine

Copy link
Copy Markdown

Package vsphere - 1.10.0 containing this change is available at https://epr.elastic.co/search?package=vsphere

@andrewkroh andrewkroh added the Integration:vsphere VMware vSphere label Jul 22, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugfix Pull request that fixes a bug issue enhancement New feature or request Integration:vsphere VMware vSphere

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants