Elk Hole Versions Save

elasticsearch, logstash and kibana configuration for pi-hole visualiziation

0.6

3 years ago

please reimport the ndjson dashboard and apply the updated version of 20-dns-syslog.conf

v0.5.1

4 years ago

fix for https://github.com/nin9s/elk-hole/issues/19

this is an intermediate release as the grok logic needs some further tweaking ...

this release fixes some major issues I've discovered which lead to incorrect mapping of log lines with tags:

  • request and query type
  • response domain to ip
  • cached domain to ip

this could lead to tagging of logs which are actually "cached domain to ip" to be categorized as "response domain to ip". From this update on you should see A LOT more cached entries than ever before.

the dashboard also needed some fixing as the request count in some visualizations where not counted correctly.

note: the file ndjson/v7.x vis and dash/elk-hole - vis_and_dash.ndjson should be imported (select overwrite) into kibanas saved objects and will include both the updated visualizations and the dashboard.

for this patch to work you only need to replace the following files:

20-dns-syslog.conf import into kibanas saved objects: elk-hole - vis_and_dash.ndjson

v0.5

4 years ago

this is an intermediate release as the grok logic needs some further tweaking ...

this release fixes some major issues I've discovered which lead to incorrect mapping of log lines with tags:

  • request and query type
  • response domain to ip
  • cached domain to ip

this could lead to tagging of logs which are actually "cached domain to ip" to be categorized as "response domain to ip". From this update on you should see A LOT more cached entries than ever before.

the dashboard also needed some fixing as the request count in some visualizations where not counted correctly.

note: the file ndjson/v7.x vis and dash/elk-hole - vis_and_dash.ndjson should be imported (select overwrite) into kibanas saved objects and will include both the updated visualizations and the dashboard.

for this patch to work you only need to replace the following files:

20-dns-syslog.conf import into kibanas saved objects: elk-hole - vis_and_dash.ndjson

0.4

4 years ago

v0.3

4 years ago
  • replaced "<field.keyword>" to "f.ield" in v7.x (this is only until I figure out what is 'wrong' with the index template)
  • the old files are still available, selectable via the suitable folder named according to the version elk-hole.zip

0.2

5 years ago

various dashboard fixes elk-hole.zip

v0.1.11

5 years ago

v0.1.1

5 years ago

elk-hole

5 years ago

elk-hole.zip

initial release