You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/integrations/amazon-aws/amazon-opensearch-service.md
+40-35Lines changed: 40 additions & 35 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -16,11 +16,11 @@ The Sumo Logic app for Amazon OpenSearch collects CloudWatch logs, CloudWatch me
16
16
17
17
The Sumo Logic app for Amazon OpenSearch uses:
18
18
19
-
* OpenSearch CloudWatch Logs. For details, see [here](https://docs.aws.amazon.com/opensearch-service/latest/developerguide/createdomain-configure-slow-logs.html).
20
-
* OpenSearch CloudWatch Metrics. For details, see [here](https://docs.aws.amazon.com/opensearch-service/latest/developerguide/managedomains-cloudwatchmetrics.html).
21
-
* OpenSearch using AWS CloudTrail. For details, see [here](https://docs.aws.amazon.com/opensearch-service/latest/developerguide/managedomains-cloudtrailauditing.html).
```sql title="Write Latency by Domain Name (Metrics-based)"
190
194
account=* region=* namespace=aws/es domainname=* !nodeid=* metric=WriteLatency statistic = average | avg by domainname
191
195
```
192
196
193
-
## **Collect logs and metrics for the Amazon OpenSearch app**
197
+
## Collect logs and metrics for the Amazon OpenSearch app
194
198
195
-
### **Collect Amazon OpenSearch CloudWatch Logs**
199
+
### Collect Amazon OpenSearch CloudWatch Logs
196
200
197
201
To enable Amazon OpenSearch CloudWatch Logs, follow the steps mentioned in [AWS Documentation](https://docs.aws.amazon.com/opensearch-service/latest/developerguide/createdomain-configure-slow-logs.html)
198
202
@@ -212,28 +216,28 @@ Sumo Logic supports several methods for collecting logs from Amazon CloudWatch.
1. Add an [AWS CloudTrail Source](https://help.sumologic.com/docs/send-data/hosted-collectors/amazon-aws/aws-cloudtrail-source/) to your Hosted Collector.
218
-
* Name. Enter a name to display for the new Source.
219
-
* Description. Enter an optional description.
220
-
* S3 Region. Select the Amazon Region for your cloudTrail S3 bucket.
221
-
* Bucket Name. Enter the exact name of your cloudTrail S3 bucket.
222
-
* Path Expression. Enter the string that matches the S3 objects you'd like to collect. You can use a wildcard (\*) in this string.
222
+
* **Name**. Enter a name to display for the new Source.
223
+
* **Description**. Enter an optional description.
224
+
* **S3 Region**. Select the Amazon Region for your CloudTrail S3 bucket.
225
+
* **Bucket Name**. Enter the exact name of your CloudTrail S3 bucket.
226
+
* **Path Expression**. Enter the string that matches the S3 objects you'd like to collect. You can use a wildcard (\*) in this string.
223
227
* DO NOT use a [leading forward slash](https://help.sumologic.com/docs/send-data/hosted-collectors/amazon-aws/amazon-path-expressions/).
224
228
* The S3 bucket name is not part of the path. Don’t include the bucket name when you are setting the Path Expression.
225
-
* Source Category. Enter a source category. For example, enter `aws/observability/CloudTrail/logs`.
226
-
* Fields. Add an account field and assign it a value that is a friendly name/alias to your AWS account from which you are collecting logs. Logs can be queried using the account field.
229
+
* **Source Category**. Enter a source category. For example, enter `aws/observability/CloudTrail/logs`.
230
+
* **Fields**. Add an account field and assign it a value that is a friendly name/alias to your AWS account from which you are collecting logs. Logs can be queried using the account field.
227
231
![Fields][image3]
228
232
* Access Key ID and Secret Access Key. Enter your Amazon [Access Key ID and Secret Access Key](http://docs.aws.amazon.com/AWSSimpleQueueService/latest/SQSGettingStartedGuide/AWSCredentials.html). Learn how to use Role-based access to AWS [here](https://help.sumologic.com/docs/send-data/hosted-collectors/amazon-aws/aws-sources/).
229
233
* Log File Discovery \-\> Scan Interval. Use the default of 5 minutes. Alternately, enter the frequency. Sumo Logic will scan your S3 bucket for new data. Learn how to configure Log File Discovery [here](https://help.sumologic.com/docs/send-data/hosted-collectors/amazon-aws/aws-sources/).
230
234
* Enable Timestamp Parsing. Select the Extract timestamp information from log file entries check box.
231
235
* Time Zone. Select Ignore time zone from the log file and instead use, and select UTC from the dropdown.
232
236
* Timestamp Format. Select Automatically detect the format.
233
237
* Enable Multiline Processing. Select the Detect messages spanning multiple lines check box, and select Infer Boundaries.
1. Configure a [Hosted Collector](https://help.sumologic.com/docs/send-data/hosted-collectors/configure-hosted-collector/).
239
243
2. Configure an [Amazon CloudWatch Source for Metrics](https://help.sumologic.com/docs/send-data/hosted-collectors/amazon-aws/amazon-cloudwatch-source-metrics/) or [AWS Kinesis Firehose for Metrics Source](https://help.sumologic.com/docs/send-data/hosted-collectors/amazon-aws/aws-kinesis-firehose-metrics-source/) (Recommended).
@@ -312,7 +316,7 @@ import AppInstall from '../../reuse/apps/app-install-v2.md';
312
316
313
317
## **Viewing Amazon OpenSearch dashboards**
314
318
315
-
### **01. Amazon OpenSearch \- Overview**
319
+
### Overview
316
320
317
321
The Amazon OpenSearch \- Overview dashboard provides a comprehensive overview of Amazon OpenSearch performance and operational metrics. It displays key information about cluster utilization, user activity, query performance, error logs, and system events. The dashboard is designed to help administrators monitor and optimize their OpenSearch deployment across different domains and regions.
The Amazon OpenSearch \- Performance Overview dashboard provides a comprehensive view of the OpenSearch cluster's health, performance, and resource utilization. It offers real-time insights into cluster status, CPU and memory usage, storage metrics, document management, and read/write latencies across different domains.
The Amazon OpenSearch \- Audit Logs \- Failed Logins dashboard provides a comprehensive view of login activities, focusing on failed login attempts and authentication errors. It offers insights into the geographical distribution of failed logins, user-specific login failures, cluster-based login issues, and detailed authentication error logs.
The Amazon OpenSearch \- Error Logs \- Garbage Collection dashboard provides a comprehensive view of garbage collection (GC) activities in AWS OpenSearch Service. It offers insights into GC performance, memory cleanup, and JVM memory usage across different domains. The dashboard helps monitor and optimize the garbage collection process, which is crucial for maintaining the performance and stability of OpenSearch clusters.
The Amazon Opensearch \- Slow Logs \- Queries dashboard provides a comprehensive view of query performance and behavior within an OpenSearch environment.
### **07. Amazon OpenSearch \- Domain Name (Cluster) Performance**
395
+
### Domain Name (Cluster) Performance
392
396
393
397
The Amazon OpenSearch \- Domain Name (Cluster) Performance dashboard provides a comprehensive view of cluster performance and resource utilization across different domains. It offers insights into node count, CPU and memory usage, request patterns, and storage metrics for OpenSearch clusters.
The Amazon OpenSearch \- Nodes Performance dashboard provides a detailed view of node-level performance metrics for OpenSearch clusters across different domains. It offers insights into search and indexing operations, threadpool activities, and overall cluster health, allowing for granular monitoring and troubleshooting of OpenSearch nodes.
411
+
408
412
Use this dashboard to:
409
413
* Compare search and indexing performance across different nodes and domains, with visualizations for search/indexing rates and latencies, helping identify potential bottlenecks or underperforming nodes.
410
414
* Monitor thread pool activities, including search queue times, rejected requests, and write queue metrics, which are crucial for understanding cluster load and capacity issues.
The Amazon OpenSearch \- EBS Volume Performance dashboard provides a comprehensive view of the performance metrics for Amazon Elastic Block Store (EBS) volumes associated with OpenSearch clusters. It displays various key performance indicators such as read and write latency, I/O operations per second (IOPS), throughput, burst balance, and disk queue depth.
418
424
419
-
The Amazon OpenSearch \- EBS Volume Performance dashboard provides a comprehensive view of the performance metrics for Amazon Elastic Block Store (EBS) volumes associated with OpenSearch clusters. It displays various key performance indicators such as read and write latency, I/O operations per second (IOPS), throughput, burst balance, and disk queue depth.
420
425
Use this dashboard to:
421
426
* Monitor read and write latency of EBS volumes to ensure optimal response times for OpenSearch operations.
422
427
* Track read and write IOPS to understand the I/O demand on your EBS volumes and identify any performance constraints.
The Amazon OpenSearch \- Cache Performance dashboard provides insights into cache performance, evictions, capacity, and memory usage, which are crucial for maintaining optimal performance of OpenSearch clusters.
432
437
433
438
Use this dashboard to:
434
-
* Performance tuning of OpenSearch clusters
435
-
* Capacity planning for cache and memory resources
436
-
* Troubleshooting cache-related issues
437
-
* Ability to correlate cache metrics with overall system performance
439
+
* Performance tuning of OpenSearch clusters.
440
+
* Capacity planning for cache and memory resources.
441
+
* Troubleshooting cache-related issues.
442
+
* Ability to correlate cache metrics with overall system performance.
0 commit comments