This sounds just fine to me. My current workflows and expectations
regarding openstack logs are still only half-formed so this is a
perfectly good time to change them and/or break them.
On 6/21/21 11:34 AM, Cole White wrote:
It has been a couple weeks since the identified dashboards were
transitioned to ECS. At this point, we're ready to fully transition
Openstack logs and turn off duplication to the legacy indexes.
To accomplish this, we intend to fully transition OpenStack logs on
Thursday, June 24th provided there are no concerns. A note will be
added to the legacy dashboards indicating the transition as well as
the cutoff date so that prior logs can still be accessed.
Please let us know if you have any questions or concerns.
On Tue, Jun 8, 2021 at 5:00 PM Cole White <cwhite(a)wikimedia.org
Hey Andrew, thanks for the help!
Those dashboards you listed now have ECS equivalents. Please have
a look when you have a chance. Note that the ECS-formatted logs
are being duplicated and these duplicated logs go back no more
than two days.
If those dashboards look good to you, let me know and we'll turn
off the duplication. Doing that will fully transition these logs
to ECS and lift the two-day retention limit.
On Thu, May 13, 2021 at 1:00 PM Andrew Bogott
<abogott(a)wikimedia.org <mailto:firstname.lastname@example.org>> wrote:
On 5/12/21 3:50 PM, Cole White wrote:
We (Observability) have identified a few OpenStack syslog
producers as prime candidates for migration to the Common
Logging Schema. We've prepared a patch
that will duplicate the currently produced OpenStack logs to
an ECS-compatible form to demo and prepare ECS-compatible
This is great! I don't think anyone is super attached to the
current format of the logs, so anything you want to do to
rework them is great. The only thing moderately interesting
about openstack logs is that they include a request ID which
is passed around and consistent across the different services;
it's very useful for tracking particular issues so it should
maintain pride of place in whatever post-processed messages we
wind up with.
What we need from you:
1. A quick review to see if we're missing anything.
Done, I've listed three more services in the patch: glance,
1. A list of Kibana dashboards and saved
searches that need
translation to use the new format.
There are a lot -- basically one per service x one per
deployment. You can find the list by searching for
'OpenStack' and then disregarding the Horizon and haproxy things.
That said, the most important dashboards are:
- OpenStack codfw1dev
- OpenStack eqiad1
- OpenStack Nova codfw1dev Control Services
- OpenStack Nova eqiad1 Control Services
- OpenStack Nova codfw1dev Compute
- OpenStack Nova eqiad1 Compute
If you run out of gas at the end of that list (or even part
way through) feel free to drop the cleanup on me and I can
decide if the other dashboards are worth updating or can be
done away with.
Thanks in advance! And as always,
questions are welcome!
Cloud-admin mailing list --cloud-admin(a)lists.wikimedia.org
To unsubscribe send an email tocloud-admin-leave(a)lists.wikimedia.org
Cloud-admin mailing list -- cloud-admin(a)lists.wikimedia.org