Splunkã®å Žåããã°ã¯è¡ã«åå²ãããããã¹ãæ å ±ã§ãã ã€ã³ããã¯ã¹äœæããã»ã¹äžããã°è¡ã¯ãã£ãŒã«ãã«åå²ãããŸããããšãã°ããname = valueãã§ãããããã¯ã«ã¹ã¿ãã€ãºå¯èœã§ãã ããã«ãç¹å¥ãªã¯ãšãªèšèªSPLã䜿çšããŠã次ã®ãã£ãŒã«ããæäœã§ããŸãïŒäžŠã¹æ¿ããéèšãèšç®ãã£ãŒã«ãã®äœæãããŒãã«ã®äœæãããšãã°SQLããŒã¿ããŒã¹ããã®å€éšèŸæžãžã®ã¢ã¯ã»ã¹ããããŠãã¡ãããããŸããŸãªã°ã©ãã®æ§ç¯ã SPLã¯åäžè¡ã ãã§ãªããè«ççã«ãå§çž®ãããŠ1è¡ã®è€æ°è¡ã®æçã«ã°ã«ãŒãåããããšãã§ããŸãã
Splunkèªèº«ãè¿°ã¹ãŠããããã«ãã·ã¹ãã ã«ãã€ã§ãä¿åãããŠãããã¹ãŠã®ãã°ã¯ãªã¯ãšã¹ãã«äœ¿çšã§ããŸããã€ãŸããã¢ãŒã«ã€ãã®æŠå¿µã¯ãããŸããã ãã¡ãããSplunkãå転ããŠãããã·ã³ïŒãã·ã³ïŒã¯ãä¿åããã³åŠçãããæ å ±ã®éãé©åã«åæ ããå¿ èŠããããŸãã
ãŸããSplunkã¯èªããããã°çšGoogleããšåŒãã§ããŸãããèªåã®æ æ²ã«ã€ããŠã¯ã³ã¡ã³ãããã«ãã®ã³ã¡ã³ããæ®ããŸãããã
ã€ã³ã¿ãŒãã§ã€ã¹Splunk-Webã ç¬èªã®Splunkã¢ããªã±ãŒã·ã§ã³ãäœæããããã®ããã«ïŒããã·ã¥ããŒãïŒãäœæã§ããŸãã Splunkã«ã¯ã¢ããªã±ãŒã·ã§ã³ã¹ãã¢ãããïŒã»ãšãã©ã¯ç¡æã§ããïŒã人æ°ã®ããã·ã¹ãã ïŒUNIX syslogãApacheãã°ãMicrosoft Exchangeãªã©ïŒãåæããããã®æ¢è£œã®èšå®ãå€æ°ãããŸãã
SplunkãœãããŠã§ã¢ã¯ãå ¬åŒWebãµã€ãããç¡æã§ããŠã³ããŒãã§ããŸãã ã©ã€ã»ã³ã¹ã¯ãã·ã¹ãã ãä»ããŠæ±²ã¿äžãããããã°ã®æ¯æ¥ã®éã«åºã¥ããŠããŸãã ç¥ãåãã«ã¯ãã·ã¹ãã ãç¿åŸããã®ã«ååãªæå°ç©ºã容éããããŸãã
ç°¡åã«åç §ã§ããããã«ããã®è£œåã®äœæè ã«ããæžç±Exploring Splunkããå§ãããŸãã ãããã¹ã¯ããŒã«ãããšãSplunkã§äœãã§ããããSPLã¯ãšãªèšèªã®æ¬è³ªãªã©ãæåã«ããç解ã§ããŸãã
ãã®èšäºã§ã¯ã30å以å ã«ç¹°ãè¿ãããšãã§ããå®éã®äŸã瀺ããããšæããŸãã ãããè¡ãã«ã¯ãã䜿çšã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã çšã®Splunkãç¡æã§ããŠã³ããŒãããŠã€ã³ã¹ããŒã«ããã ãã§ååã§ãã ãã®åŸãç§ã®æ瀺ã«åŸã£ãŠãã ããã
äŸã¯çããã§ãããã åŸæ¥ããã°ã¯å±¥æŽæ å ±ã®åæã«äœ¿çšãããŠããŸããã ãããããã®åºçŸã®éçšã§ãããæœåºããããã«åºã¥ããŠãã©ã€ããã€ã³ãžã±ãŒã¿ãäœæããããšã劚ãããã®ã¯ãããŸããã ç§ã®äŸã¯å°ã人工çã§ãããSplankã«ããŒã¿ããã¢ããããŒããããããã圢åŒåããããã«åºã¥ããŠåçãªãŠãŒã¶ãŒã€ã³ã¿ãŒãã§ãŒã¹ãæ§ç¯ã§ããããšãã©ãã ãè¿ éãã€ç°¡åã«ç€ºããããšæããŸãã
ããŒã»ã³ããŒãžïŒ0ã100ïŒ ïŒãå«ãã¡ãã»ãŒãžã1åéãã°ã«èšé²ããç°¡åãªã¹ã¯ãªããã次ã«ç€ºããŸãã
require 'date' duration = 60*1 update_period = 0.5 i = 0 while i <= duration do progress = i * 100.0 / duration msg = "%s progress=%05.2f\n" % [DateTime.now, progress] puts msg open("logs/my.log", 'a') { |f| f << msg } i = i + update_period sleep update_period end
ãã°ã¯æ¬¡ã®ããã«ãªããŸãã
2012-11-23T15:58:54+00:00 progress=45.00 2012-11-23T15:58:55+00:00 progress=45.83 2012-11-23T15:58:55+00:00 progress=46.67 2012-11-23T15:58:56+00:00 progress=47.50 2012-11-23T15:58:56+00:00 progress=48.33 2012-11-23T15:58:57+00:00 progress=49.17 2012-11-23T15:58:57+00:00 progress=50.00
ç§ãã¡ã®ç®æšã¯ãSplanã«ããã·ã¥ããŒãïŒè¡šç€ºããã«ïŒãäœæãããã°ããããŒã¿ãååŸããªãããã¹ã¯ãªããå®è¡ããã»ã¹ãçŸããã€ã³ãžã±ãŒã¿ãŒã®åœ¢ã§è¡šç€ºããããšã§ãã
ç°¡åã«ããããã«ã1å°ã®ãã·ã³ã§ãã¹ãŠãå®è¡ããSplankã¯æå®ããããã¡ã€ã«ããã®ã¿ãã°ãååŸããŸãã
ãã®ãããSplankã¯ãã§ã«ã€ã³ã¹ããŒã«ãããŠãããã httpïŒ// localhostïŒ8000 ãã«ç§»åãããšãSplankã®äœæ¥ããŒãžã衚瀺ããããŠãŒã¶ãŒãadminãã§ãã°ã€ã³ã§ããŸãã
次ã«ãã¡ãã¥ãŒã«ç§»åããŸãïŒããããŒãžã£ãŒ->ããŒã¿å ¥å->ããŒã¿ã®è¿œå ->ãã¡ã€ã«ãŸãã¯ãã£ã¬ã¯ããªãŸãã¯ãã¡ã€ã«ãã ããã§ããã°ãä¿åãããŠãããã¡ã€ã«ãŸãã¯ãã£ã¬ã¯ããªã®ååãæå®ããŸãïŒãã®å Žåã¯åäžã®ãã¡ã€ã«ã«ãªããŸãïŒã
ãããããã°ã®ãœãŒã¹ïŒãœãŒã¹ã¿ã€ãïŒã®äœæã確èªããŸãã ãã§ã«è¿°ã¹ãããã«ããã°ã¯ããŸããŸãªæ¹æ³ã§Splankã«éãããŸãã ãã®ãããªåãã°ãœãŒã¹ã«ã¯ååãä»ããããåå¥ã«åŠçã§ããŸãã
ãã®ããããã°ãè¿œå ãããŸãã Splankããã¡ã€ã«ããããã¯ã¢ããããããã§ã«è¡ããã£ãŒã«ãã«è§£æããŠããããšãããããŸãã Splankã¯èšå€§ãªæ°ã®æ¥ä»ãšæå»ã®åœ¢åŒãç解ããŠããŸãããããã¯åºå·ããŠããŸãã
次ã«ããã°ãœãŒã¹ã«ååãtest_loggingããä»ããŠãèšå®ãä¿åããŸãã
ã¡ã€ã³ããŒãžã«æ»ããSearchè¡ã«æåã®ã¯ãšãªãSPLèšèªïŒèµ€ïŒã§å ¥åããŸãã
sourcetype = "test_logging" | ãããŒããšããŠã®ããŒãã«ã®é²è¡ç¶æ³
ç§ã¯ç¿»èš³ããŸãïŒãœãŒã¹ãtest_loggingããããã°ãååŸãããã£ãŒã«ããprogressãããã®å€ã§åãè¿œå ããããŒãã«ãäœæããåæã«ãããŒãåã«å€æããŸãã äžïŒéè²ïŒã«ã¯ãã¯ãšãªã®çµæã衚瀺ãããŠããŸãïŒãã°ã«ã¯æ¢ã«ããŒã¿ããããŸãïŒã UNIXãã€ãïŒ|ïŒã®åçã¯ãããæäœã®çµæã次ã®æäœã®å ¥åã«æž¡ããããšãã«SPLã§æ©èœããŸãã
ã ããããŒãã«ããããŸãã 次ã«ã圌女ãã°ã©ãã£ã«ã«ãªè¡šçŸã«ããŸãã ããšãã°ã0ã100ã®å®äºçã瀺ããã£ãŒã«ãã1ã€ãããªããããé床èšã®ã¿ã€ãã䜿çšã§ããŸãããã®é床ã®ç¢å°ã¯çŸåšã®å€ã瀺ããŸãã [æžåŒèšå®ãªãã·ã§ã³]ïŒéè²ïŒãã¯ãªãã¯ããèŠçŽ ã®çš®é¡ïŒã°ã©ãã®çš®é¡ïŒ[æŸå°ç¶ã²ãŒãž]ïŒèµ€è²ïŒãéžæããŸãã ããã«ãã®ãããªçŸããã¹ããŒãã¡ãŒã¿ãŒããããŸãã
æåã®ãŠã£ãžã§ããã®æºåãã§ããŸããã å®éšã®ããã«ããã1ã€äœæããŸãã é²è¡ç¶æ³ãã£ãŒã«ãã®å€ã衚瀺ãããŸãããå·Šããå³ã«ç§»åããæ°Žå¹³ã€ã³ãžã±ãŒã¿ïŒé²è¡ç¶æ³ããŒïŒã®åœ¢åŒã§è¡šç€ºãããŸãã ãã®å Žåã®ãªã¯ãšã¹ãã¯æ¬¡ã®ããã«ãªããŸãã
sourcetype = "test_logging" | ããŒãã«_timeé²æ| é 1
æå³ïŒãœãŒã¹ãtest_loggingãããã®ããŒã¿ã«åŸã£ãŠãã_ timeããšãprogressãã®2ã€ã®ãã£ãŒã«ãã®ããŒãã«ãäœæããããããæåã®è¡ã®ã¿ãååŸããŸãã ããã©ã«ãã®ãœãŒãã¯ããã£ãŒã«ãã_timeãã«ããéé ã§ãã 以äžïŒç·è²ïŒã«ããã®ã¯ãšãªã®çµæã衚瀺ãããŸãã
次ã«ãããã©ãŒããããªãã·ã§ã³ããã¯ãªãã¯ããã¿ã€ããããŒãïŒç·è²ïŒãéžæããY軞ã®ééã0ãã100ã«èšå®ããŸããäœããã®çç±ã§ãX軞ãåçŽã«ãªãïŒã_timeããã£ãŒã«ãã衚瀺ãããŸãïŒãY軞氎平æ¹åïŒãé²è¡ç¶æ³ããã£ãŒã«ããããã«è¡šç€ºãããŸãïŒã åã®å³ã®ãªã¯ãšã¹ãã¯å€100ã瀺ããŠãããããæ°Žå¹³ã€ã³ãžã±ãŒã¿ãŒã¯å®å šã«åããããŸãã
æåã®ãŠã£ãžã§ããã§ããã¹ããŒãã¡ãŒã¿ãŒã§ã¯ãããã¹ãããããŸãããããããã°ããããªã¯ãšã¹ããšãã®èŠèŠçè¡šçŸã¯ãããã·ã¥ããŒãããã«ããšããŠä¿åã§ããŸãã ãããè¡ãã«ã¯ããäœæãããã³ãããã·ã¥ããŒãããã«.ââ..ãïŒèµ€ïŒãã¯ãªãã¯ããŠãèšå®ãä¿åããŸãã æåã®ãŠã£ãžã§ããã«ãSpeedometerãã2çªç®ã®ãProgress barãã«ååãä»ããŸãããã
æåã®ãŠã£ãžã§ãããä¿åãããšãã«ãããã·ã¥ããŒããäœæããããšãã§ããŸãããããããã¹ããã®ã³ã°ããšåŒã³ãŸãããã 2çªç®ã®ãŠã£ãžã§ãããä¿åãããšãã«ãæ¢ã«äœæãããŠããããã«ãè¿œå ããŸãã
ããã«ãäœæããåŸããããã·ã¥ããŒããšãã¥ãŒããã¯ãªãã¯ããããã¹ããã®ã³ã°ããšããååã§éžæã§ããŸãã å€èŠ³ã¯æ¬¡ã®ããã«ãªããŸãã
ãŸã ããŒã¿ããªããããããã«ã¯ç©ºã§ãã ããã«ã®ååïŒèµ€è²ïŒããŠã£ãžã§ããã®ååïŒé»è²ïŒãããã«ãã¢ã¯ãã£ãã«ãããã¿ã³ïŒç·è²ïŒãããã³ã¯ãšãªãŸãã¯èŠèŠçãªãã¬ãŒã³ããŒã·ã§ã³ããã®å Žã§ä¿®æ£ã§ãããç·šéããã¿ã³ïŒéè²ïŒã衚瀺ãããŸãã ã¹ã¯ãªãããéå§ããåã«ããç·šéããã¿ã³ããåãŠã£ãžã§ããã«ç§»åãã1ç§ã®æŽæ°æéééãæå®ããå¿ èŠããããŸãïŒãrt-1sãïŒãªã¢ã«ã¿ã€ã -1sïŒãããrtãïŒçŸåšã®æéïŒãŸã§ã
ããã§ããªãã¯è¡ãââãŸãïŒ ããªã³ãã«åºå®ããŠãã¹ã¯ãªãããå®è¡ããŸãã
ä»çµã¿ã®ãããªïŒ
ããã ãã§ãïŒ
ãããã«
ãã¡ããããã®äŸã¯éåžžã«åçŽã§ãããSplankãã©ã®ããã«æ©èœãããã«ã€ããŠå°ãªããšãæå°éã®æèŠãäŒããããšãã§ãããšæããŸãã
äŒç€Ÿã§æè¿ãã®è£œåã䜿ãå§ããŠãä»ã®ãšããæºè¶³ããŠãããšèšããŸãã ä»å¹Žãç§ã¯éåžžã«è©å€ã®è¯ãããªãã£ãã·ã¥ãã¬ã³ã ã¿ã€ãã®äŒæ¥ã®äººã ãåºæŒããSplunkLiveã«ã³ãã¡ã¬ã³ã¹ã«åå ããŸããã Splunkã§ã¯ãæ¯æ¥æ°ã®ã¬ãã€ãã®ãã°ãåŠçããŸãã
æ®å¿µãªããã倧èŠæš¡ãªãªãã£ã¹ã§ãã£ãŠãããã°ãåŠçããããã®ãµãã·ã¹ãã ãéçºããããšããèŠæãåžžã«ããããã§ã¯ãªããããSplankã圹ç«ã¡ãŸãã