Logstash Basics

Logstash์— ๋Œ€ํ•ด ์•Œ์•„๋ณด์•„์š”์šฐ

Reference: Logstash docs

What is Logstash?

Logstash

  • Real-time pipeline ๊ธฐ๋Šฅ์„ ๊ฐ€์ง„ open source data collection engine

  • ์„œ๋กœ ๋‹ค๋ฅธ data source๋ฅผ dynamicํ•˜๊ฒŒ ํ†ตํ•ฉํ•˜๊ณ , ์ง€์ •ํ•œ ๋ชฉ์ ์ง€๋กœ data๋ฅผ ์ •๊ทœํ™” ํ•  ์ˆ˜ ์žˆ๋‹ค

  • Data๋ฅผ cleanseํ•˜๊ณ  democratize ํ•  ์ˆ˜ ์žˆ๋‹ค

The Power of Logstash

1. Elasticsearch ๋“ฑ์„ ์œ„ํ•œ ๊ฐ•๋ ฅํ•œ ์ˆ˜์ง‘ ๊ธฐ๋Šฅ

์‹œ๋„ˆ์ง€ ํšจ๊ณผ๋ฅผ ๋ฐœํœ˜ํ•˜๋Š” Elasticsearch์™€ Kibana๋ฅผ ํ™œ์šฉํ•œ ์ˆ˜ํ‰ ํ™•์žฅ ๊ฐ€๋Šฅํ•œ data processing pipeline

2. Pluggable pipeline architecture

๋‹ค์–‘ํ•œ input, filter, output์„ mix & matchํ•˜๊ณ  ์กฐ์ •ํ•˜๋ฉด์„œ pipeline์—์„œ ์กฐํ™”๋กญ๊ฒŒ ์šด์šฉ ๊ฐ€๋Šฅ

3. Community-extensible and developer-friendly plugin ecosystem

200์—ฌ๊ฐœ์˜ plugin ์‚ฌ์šฉ ๊ฐ€๋Šฅ & ์ง์ ‘ plugin์„ ๋งŒ๋“ค์–ด ์ œ๊ณตํ•  ์ˆ˜๋„ ์žˆ๋Š” ์œ ์—ฐ์„ฑ๋„ ๊ฐ–๊ณ  ์žˆ์Œ

Logstash Loves Data

  • ๋” ๋งŽ์€ data๋ฅผ ์ˆ˜์ง‘ํ• ์ˆ˜๋ก ๋” ๋งŽ์ด ์•Œ ์ˆ˜ ์žˆ๋‹ค

  • Logstash๋Š” ๋ชจ๋“  ํ˜•ํƒœ ๋ฐ ๊ทœ๋ชจ์˜ data๋ฅผ ๋‹ค๋ฃฐ ์ˆ˜ ์žˆ๋‹ค

Logs and Metrics

๋ชจ๋“ ๊ฒƒ์ด ์‹œ์ž‘๋˜๋Š” ๊ณณ

  • ๋ชจ๋“  ์œ ํ˜•์˜ logging data ์ฒ˜๋ฆฌ ๊ฐ€๋Šฅ

    • ๋‹ค์–‘ํ•œ web log (ex. Apache) ๋ฐ appliction log (ex. log4j for Java) ๋ฅผ ์ˆ˜์ง‘ํ•œ๋‹ค

    • syslog, networking๊ณผ firewall log ๋“ฑ ์—ฌ๋Ÿฌ ํ˜•์‹์˜ log๋ฅผ ์ˆ˜์ง‘ํ•œ๋‹ค

  • Filebeat์™€ ์—ฐ๊ณ„ํ•˜์—ฌ ๋ณด์•ˆ์„ ์œ ์ง€ํ•˜๋ฉฐ log๋ฅผ ์ „๋‹ฌํ•  ์ˆ˜ ์žˆ๋‹ค

The Web

World Wide Web์˜ ์ง„์ •ํ•œ ํšจ์šฉ์„ฑ ์‹คํ˜„

  • HTTP requests๋ฅผ event๋กœ ๋ณ€ํ™˜

    • Social sentiment ๋ถ„์„์„ ์œ„ํ•ด Twitter ๋“ฑ์˜ firehose ์‚ฌ์šฉ

    • Github, Jira๋ฅผ ๋น„๋กฏํ•œ ์ˆ˜๋งŽ์€ application์„ ์œ„ํ•œ webhook ์ง€์›

    • ๋‹ค์–‘ํ•œ Watcher์•Œ๋ฆผ ํ™œ์šฉ ์‚ฌ๋ก€ ์ง€์›

  • ํ•„์š”์— ๋”ฐ๋ผ HTTP ์—”๋“œํฌ์ธํŠธ polling์œผ๋กœ event ์ƒ์„ฑ

    • web application interface๋กœ๋ถ€ํ„ฐ ์ƒํƒœ, ์„ฑ๋Šฅ, metric ๋ฐ ๊ธฐํƒ€ ๋ฐ์ดํ„ฐ ์œ ํ˜•์„ ์ˆ˜์ง‘ํ•œ๋‹ค

Data Stores and Streams

์ด๋ฏธ ๋ณด์œ ํ•˜๊ณ  ์žˆ๋Š” data์—์„œ ๋” ํฐ ๊ฐ€์น˜๋ฅผ ๋ฐœ๊ตดํ•˜๊ธฐ

  • JDBC interface๋ฅผ ํ†ตํ•ด ๊ด€๋ จ database ๋˜๋Š” NoSQL ์ €์žฅ์†Œ์˜ ๋ฐ์ดํ„ฐ๋ฅผ ๋” ์ •ํ™•ํžˆ ์ดํ•ดํ•  ์ˆ˜ ์žˆ๋‹ค

  • Apache Kafka, RabbitMQ, Amazon SQS, ZeroMQ ์™€ ๊ฐ™์€ messaging queue๊ฐ€ ์ œ๊ณตํ•˜๋Š” ๊ฐ์ข… data stream์„ ํ†ตํ•ฉํ•  ์ˆ˜ ์žˆ๋‹ค

Easily Enrich Everything

  • ๋” ๋‚˜์€ data๋กœ ๋” ๋‚˜์€ knowledge๋ฅผ ์–ป๊ธฐ

    • ์ƒ‰์ธ ๋˜๋Š” ์ถœ๋ ฅ ์‹œ์ ์— ๊ฑฐ์˜ ์‹ค์‹œ๊ฐ„์œผ๋กœ insight๋ฅผ ํ™•๋ณดํ•  ์ˆ˜ ์žˆ๋„๋ก ์ˆ˜์ง‘ ๊ณผ์ •์— ๋ฐ์ดํ„ฐ๋ฅผ ์ •๋ฆฌํ•˜๊ณ  ๋ณ€ํ™˜ํ•œ๋‹ค

    • Logstash๋Š” pattern matching, geo mapping, dynamic lookup ๊ธฐ๋Šฅ ๋“ฑ๊ณผ ํ•จ๊ป˜ ๋‹ค์–‘ํ•œ ์ง‘๊ณ„ ๋ฐ ๋ณ€์ด ๊ธฐ๋Šฅ์„ ์ œ๊ณตํ•œ๋‹ค

Last updated