GithubHelp home page GithubHelp logo

donfanning / haraka-plugin-elasticsearch Goto Github PK

View Code? Open in Web Editor NEW

This project forked from haraka/haraka-plugin-elasticsearch

0.0 1.0 0.0 95 KB

Ship Haraka log info directly to Elasticsearch

Home Page: https://www.npmjs.com/package/haraka-plugin-elasticsearch

License: MIT License

JavaScript 100.00%

haraka-plugin-elasticsearch's Introduction

Build Status Code Climate NPM

haraka-plugin-elasticsearch

Ship Haraka log info directly to Elasticsearch

INSTALL

cd /path/to/local/haraka
npm install haraka-plugin-elasticsearch
echo "elasticsearch" >> config/plugins
service haraka restart

Configuration

If the default configuration is not sufficient, copy the config file from the distribution into your haraka config dir and then modify it:

cp node_modules/haraka-plugin-elasticsearch/config/elasticsearch.ini
config/elasticsearch.ini
$EDITOR config/elasticsearch.ini

Logging

Unless errors are encountered, no logs are emitted.

Errors

The elasticsearch module has very robust error handling built in. If there's a connection issue, errors such as these will be emitted when Haraka starts up:

  • Elasticsearch cluster is down!
  • No Living connections

However, ES will continue attempting to connect and when the ES server(s) are available, logging will begin. If errors are encountered trying to save data to ES, they look like this:

  • No Living connections
  • Request Timeout after 30000ms

They normally fix themselves when ES resumes working properly.

Configuration

  • host - an IP or hostname of the ES server to connect to

    host=127.0.0.2

  • pluginObject

By default, all plugin results are presented as $plugin_name: { ... }, at the top level. If you prefer that all plugin results be nested inside an object $obj: { $plugin_name: { ...}, set pluginObject to that object's key name

pluginObject=plugin
  • [ignore_hosts]

A config file section for hosts whose results should not be stored in ES. HAproxy servers, Nagios, and other hosts who monitor Haraka can be listed here. The format for entries is host.name=true

  • [index]

    transaction=smtp-transaction connection=smtp-connection

Transactions include all the connection information and are "the good stuff." When a connection has transactions, the connection is not saved separately. The distinction is that a connection is stored only when it has zero transactions. The connections index tends to be mostly noise (monitoring, blocked connections, bruteforce auth attempts, etc.). To collapse them into the same index, set the value for both identically.

Index map template

Creating a map template will apply the template(s) to any future indexes that match the pattern/name in the template setting. This is how to manually apply an index map template from the sample file in this package:

curl -X PUT 'http://localhost:9200/_template/haraka_results' -H 'Content-Type: application/json' -d @index-map-template.json

haraka-plugin-elasticsearch's People

Contributors

dexus avatar greenkeeper[bot] avatar msimerson avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.