Skip to content

[doc] Logstash Kubernetes - Stack Monitoring docs - #14696

Merged
kaisecheng merged 35 commits into
elastic:mainfrom
kaisecheng:doc_k8s_stack_monitoring
Nov 4, 2022
Merged

kaisecheng merged 35 commits into
elastic:mainfrom
kaisecheng:doc_k8s_stack_monitoring

Conversation

@kaisecheng

@kaisecheng kaisecheng commented Oct 25, 2022 •

Copy link
Copy Markdown
Contributor
  • introduction
  • use metricbeat with autodiscover to monitor multiple Logstashes.
  • send metrics to external ES cluster
  • send metrics to Elastic Cloud

For agent/metricbeat monitoring logstash, we have a recipe in beats for stack monitoring while agent is missing this part. Also, we have "Elasticsearch Metrics" integrations for beats but not agent. Agent can monitor Logstash with limitation. If users want to monitor multiple logstashes, they need to assign different service name for each logstash which is not practical. So, in this doc, agent is not mentioned as a solution.

I wanna have stack monitoring in multiple pages as the following structure without success. They are on the same page now. If you know how to split it, please let me know.

Administering
|_ Stack Monitoring
     |_ Ship metrics to external cluster
     |_ Ship metric to Elastic Cloud

Fixes: #14572

@kaisecheng
kaisecheng marked this pull request as ready for review October 26, 2022 15:20
@kaisecheng
kaisecheng requested a review from robbavey October 26, 2022 15:29
@robbavey

Copy link
Copy Markdown
Member

jenkins test this please

@robbavey robbavey left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice work - I have a couple of questions on structure and formatting

To enable {logstash-ref}/monitoring-with-metricbeat.html[Stack Monitoring] for {ls}, you need Metricbeat to collect {ls} metrics, {es} to store the metrics and Kibana to view the result.

Follow these steps to configure monitoring:
Assuming you have installed ECK, the example modifies the link:https://github.com/elastic/cloud-on-k8s/blob/main/config/recipes/beats/stack_monitoring.yaml[recipe] of Beats stack monitoring. The recipe has initiated a production {es} cluster, a monitoring {es} cluster, {filebeat}, {metricbeat}, a production Kibana and a monitoring Kibana. It monitors {es} and Kibana and send metrics to monitoring cluster.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I wonder if we should call out ECK explicitly, but have an intro section, explaining what we are doing here with these examples:

Something like,

For these examples, we will be modifying the Beats stack monitoring link:https://github.com/elastic/cloud-on-k8s/blob/main/config/recipes/beats/stack_monitoring.yaml[recipe] from the ECK examples, which initiate ...

And then have

=== Stack Monitoring with ECK

Or something along those lines.

Thoughts @karenzone ?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we can add a note of prerequisites of installing ECK which links to the Quick start set up environment

An important step to making your environment production ready is to configure stack monitoring. Monitoring metrics can be sent to an external resource, such as {ess} or {eck}, so that in the event that any components of your environment become unresponsive, your monitoring data is available.

An important step to making your environment production ready is to configure stack monitoring. Monitoring logs and metrics data can be sent to an external resource, such as {ess} or {eck}, so that in the event that any components of your environment become unresponsive, your monitoring data is available.
To enable {logstash-ref}/monitoring-with-metricbeat.html[Stack Monitoring] for {ls}, you need Metricbeat to collect {ls} metrics, {es} to store the metrics and Kibana to view the result.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I wonder if we should start with some prerequisites - for the elastic cloud or external cluster options, we require that the elastic CRD's are installed ahead of time, to ensure that the Beat CRD is available. Maybe call it out ahead of time before we have sections for ECK/Elastic Cloud/External Elasticsearch?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

agree, will do it

Comment thread docsk8s/administering/ls-k8s-stack-monitoring-cloud.asciidoc Outdated
Comment thread docsk8s/administering/ls-k8s-stack-monitoring.asciidoc Outdated

<2> {metricbeat} scans for the pods with label `app: ls` to collect {ls} metrics.

<3> {metricbeat} logstash module calls metric endpoint from port `9600` for every `10` seconds.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Does it call each logstash every 10 seconds? Or round robin between them, so for 3 logstashes, every 30 seconds?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

it calls each logstash every 10 seconds

...
--

Provide the `cluster_uuid` of the production {es} cluster to `monitoring.cluster_uuid` in logstash.yml.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we have a link anywhere on how to do that?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I added instructions of getting uuid

@roaksoax roaksoax changed the title [Doc] k8s stack monitoring [doc] Logstash Kubernetes - Stack Monitoring docs Oct 31, 2022
kaisecheng and others added 2 commits November 1, 2022 10:58
Co-authored-by: Rob Bavey <rob.bavey@elastic.co>
Co-authored-by: Rob Bavey <rob.bavey@elastic.co>
@github-actions

github-actions Bot commented Nov 1, 2022

Copy link
Copy Markdown
Contributor

📃 DOCS PREVIEW ✨ https://logstash_14696.docs-preview.app.elstc.co/diff

add instruction of getting cluster_uuid
@github-actions

github-actions Bot commented Nov 1, 2022

Copy link
Copy Markdown
Contributor

📃 DOCS PREVIEW ✨ https://logstash_14696.docs-preview.app.elstc.co/diff

@github-actions

github-actions Bot commented Nov 1, 2022

Copy link
Copy Markdown
Contributor

📃 DOCS PREVIEW ✨ https://logstash_14696.docs-preview.app.elstc.co/diff

@kaisecheng
kaisecheng requested a review from robbavey November 1, 2022 13:56
[[ls-k8s-monitor-external]]
==== Ship metrics to external {es} cluster

NOTE: The prerequisite of the example is having ECK installed. Checkout <<qs-set-up>>

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is it a prerequisite to have ECK installed? Or just the CRDs?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The example involves the deployment of stack, so it is ECK

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think I get confused between Metrics can be sent to an {es} cluster that is not managed by ECK, and the prerequisite of ECK for this - one use case is for a new logstash cluster sending to a pre-existing monitoring cluster, not migrated to ECK

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You are right, to config the external ES we just need CRDs. I mess up with another example.

Comment thread docsk8s/administering/ls-k8s-stack-monitoring-external.asciidoc Outdated
[[ls-k8s-monitor-elastic-cloud]]
==== Ship metrics to Elastic Cloud

NOTE: The prerequisite of the example is having ECK installed. Checkout <<qs-set-up>>

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is it a prerequisite to have ECK installed? Or just the CRDs?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I am not sure how much the operator has been involved in associating Beat with Elasticsearch. I am hesitant to suggest users install CRD only. So, the prerequisite is ECK.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do you mean from the perspective of whether the Beats CRD can be used in isolation, without any of the other components of the stack?

It feels like it might be a common use case to not want to install any of the other stack elements, and just use K8s as a container for Logstash (and metricbeat to monitor it), and to send to Elastic Cloud. In which case we'd need only the sections with metadata.name: metricbeat sections, and not any of the filebeat, elasticsearch or kibana sections. And we wouldn't need the elasticsearch and kibana modules in the metricbeat definition.
And it might make sense to add this as a recipe to refer back to, to reduce the confusion with the rest of the file?

WDYT?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I probably mess up the example when I replied. This should be valid to say CRDs as a prerequisite.

My understanding of ECK includes two parts. 1. CRD 2. operator. In order to have CRDs work with full functionality, we need both. The part I was uncertain is which features/configs need operator to work, so hesitate to just suggest installing CRD. But in this feature connecting to Elastic Cloud, I think we are safe to require CRD only.

Comment thread docsk8s/administering/ls-k8s-stack-monitoring.asciidoc Outdated
Comment thread docsk8s/administering/ls-k8s-stack-monitoring.asciidoc Outdated
kaisecheng and others added 3 commits November 3, 2022 13:40
Co-authored-by: Rob Bavey <rob.bavey@elastic.co>
Co-authored-by: Rob Bavey <rob.bavey@elastic.co>
Co-authored-by: Rob Bavey <rob.bavey@elastic.co>
@github-actions

github-actions Bot commented Nov 3, 2022

Copy link
Copy Markdown
Contributor

📃 DOCS PREVIEW ✨ https://logstash_14696.docs-preview.app.elstc.co/diff

kaisecheng and others added 6 commits November 4, 2022 13:26
Co-authored-by: Karen Metts <35154725+karenzone@users.noreply.github.com>
Co-authored-by: Karen Metts <35154725+karenzone@users.noreply.github.com>
Co-authored-by: Karen Metts <35154725+karenzone@users.noreply.github.com>
Co-authored-by: Karen Metts <35154725+karenzone@users.noreply.github.com>
Co-authored-by: Karen Metts <35154725+karenzone@users.noreply.github.com>
Co-authored-by: Karen Metts <35154725+karenzone@users.noreply.github.com>
@github-actions

github-actions Bot commented Nov 4, 2022

Copy link
Copy Markdown
Contributor

📃 DOCS PREVIEW ✨ https://logstash_14696.docs-preview.app.elstc.co/diff

kaisecheng and others added 9 commits November 4, 2022 15:16
…oc_k8s_stack_monitoring

# Conflicts:
#	docsk8s/administering/ls-k8s-stack-monitoring-cloud.asciidoc
Co-authored-by: Karen Metts <35154725+karenzone@users.noreply.github.com>
Co-authored-by: Karen Metts <35154725+karenzone@users.noreply.github.com>
Co-authored-by: Karen Metts <35154725+karenzone@users.noreply.github.com>
Co-authored-by: Karen Metts <35154725+karenzone@users.noreply.github.com>
Co-authored-by: Karen Metts <35154725+karenzone@users.noreply.github.com>
@kaisecheng
kaisecheng requested a review from karenzone November 4, 2022 15:32
@github-actions

github-actions Bot commented Nov 4, 2022

Copy link
Copy Markdown
Contributor

📃 DOCS PREVIEW ✨ https://logstash_14696.docs-preview.app.elstc.co/diff

@kaisecheng
kaisecheng requested a review from robbavey November 4, 2022 16:46

@robbavey robbavey left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Really close!

Comment thread docsk8s/administering/ls-k8s-stack-monitoring-cloud.asciidoc Outdated
Comment thread docsk8s/administering/ls-k8s-stack-monitoring-external.asciidoc Outdated
[[ls-k8s-monitor-config-ls]]
===== Configure {ls}

Add label `app: ls` to `Deployment` for autodiscover.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we need to mention StatefulSet here too?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think it is optional

kaisecheng and others added 2 commits November 4, 2022 18:48
Co-authored-by: Rob Bavey <rob.bavey@elastic.co>
Co-authored-by: Rob Bavey <rob.bavey@elastic.co>
@github-actions

github-actions Bot commented Nov 4, 2022

Copy link
Copy Markdown
Contributor

📃 DOCS PREVIEW ✨ https://logstash_14696.docs-preview.app.elstc.co/diff

@robbavey robbavey left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Nice job!

@karenzone karenzone left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I revamped a suggestion from the previous review based on the clarification you provided (that "it" means "Metricbeat." Other than adding/committing that one, LGTM! 🚀


NOTE: The prerequisite of the example is having CRDs installed. Checkout <<qs-set-up>>

Metrics can be sent to an {es} cluster that is not managed by ECK. To configure it, remove the `elasticsearchRef` from the specification and include an output configuration in the `spec.config`.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the info. I updated the suggestion to clarify. :-)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Kubernetes Guidelines Documentation - Operating Logstash - Stack Monitoring

4 participants