Este producto no es compatible con el sitio Datadog seleccionado. ().
Disponible para:

Registros

Descripción general

Utilice la fuente Logstash de Observability Pipelines para recibir registros de su agente Logstash.

También puede utilizar la fuente Logstash para enviar registros a Observability Pipelines usando Filebeat.

Requisitos previos

To use Observability Pipelines’ Logstash source, you need the following information available:

  • Logstash address, such as 0.0.0.0:8088. The Observability Pipelines Worker listens on this bind address to receive logs from your applications. Later on, you configure your applications to send logs to this address.
  • The appropriate TLS certificates and the password you used to create your private key, if your forwarders are globally configured to enable SSL.

Configuración

Para la gestión de secretos: solo ingrese los identificadores para la dirección de Logstash y, si corresponde, la frase de contraseña de la clave TLS. No ingrese los valores reales.

Configure esta fuente cuando configure una canalización. Puede configurar un pipeline en la UI, utilizando la API o con Terraform. Las instrucciones de esta sección son para configurar la fuente en la interfaz de usuario.

Después de seleccionar la fuente Logstash en la pipeline UI, ingrese el identificador para su dirección de Logstash. Si lo deja en blanco, se utiliza el predeterminado.

If you enter secret identifiers and then choose to use environment variables, the environment variable is the identifier entered and prepended with DD_OP_. For example, if you entered PASSWORD_1 for a password identifier, the environment variable for that password is DD_OP_PASSWORD_1.

Configuración de TLS opcional

Toggle the switch to Enable TLS.

  • If you are using Secrets Management, enter the identifier for the key pass. See Secret defaults for the default used if the field is left blank.
  • Enter the following certificate and key files:
    • Server Certificate Path: The path to the certificate file that has been signed by your Certificate Authority (CA) root file in DER, PEM, or CRT (X.509).
    • (Optional) CA Certificate Path: The path to the certificate file that is your Certificate Authority (CA) root file in DER, PEM, or CRT (X.509).
    • (Optional) Private Key Path: The path to the .key private key file that belongs to your Server Certificate Path in DER, PEM, or CRT (PKCS #8) format.
    • Notes:
      • The configuration data directory /var/lib/observability-pipelines-worker/config/ is automatically appended to the file paths. See Advanced Worker Configurations for more information.
      • The file must be readable by the observability-pipelines-worker group and user.
  • (Optional) Toggle Verify certificate to require connecting clients to present a valid client certificate. This enforces mutual TLS (mTLS), where the Worker verifies the identity of each connecting client.

Valores predeterminados de Secret

These are the defaults used for secret identifiers and environment variables.

  • Identificador de dirección de Logstash:
    • Hace referencia a la dirección en la que Observability Pipelines Worker escucha los mensajes de registro entrantes.
    • El identificador predeterminado es SOURCE_LOGSTASH_ADDRESS.
  • Identificador de frase de contraseña TLS de Logstash (cuando TLS está habilitado):
    • El identificador predeterminado es SOURCE_LOGSTASH_KEY_PASS.
  • Logstash address and port:
    • The Observability Pipelines Worker listens on this address, such as 0.0.0.0:9997, for incoming log messages.
    • The default environment variable is DD_OP_SOURCE_LOGSTASH_ADDRESS
  • Logstash TLS passphrase:
    • The default environment variable is DD_OP_SOURCE_LOGSTASH_KEY_PASS.

Envíe registros al Observability Pipelines Worker a través de Logstash

To configure Logstash to send logs to the Observability Pipelines Worker, use the following output configuration:

output {
  http {
    url => "http://127.0.0.1:9997"
    http_method => "post"
    format => "json"
  }
}

Note: Logstash requires SSL to be configured.