elasticsearchmonitoringelastic-stackelastic-beats

Is Elastic/Metricbeats suitable for process monitoring and alerting?


Do you use Elastic and Metricbeats for process monitoring and alerting? How did you configure your data gathering and alerting?

I am currently trying to set this up, and running into some basic issues. These issues are making me question whether Elastic is a suitable tool for alerting. Here is my planned setup:

I have been working my way through this using the following approach:

The difficulties I am encountering are making me wonder if I am "doing it wrong"? Is Elastic/Metricbeats a suitable tool for what I am trying to achieve?


Solution

  • Answer: find the right hammer!

    What I needed is called "Elastic runtime fields". There's a step-by-step writeup here: https://elastic-content-share.eu/elastic-runtime-field-example-repository/

    Summary:

    PS: I deleted my logstash filters, because they were superfluous.