General workflow¶
- Data view first: in Stack Management → Data views, create one for the data stream (for example
logs-opnsense-*, time field@timestamp). - Explore in Discover: narrow the query until the documents are the ones the panel should show.
- Dashboards → Create → Create visualization opens Lens. Drag fields onto the canvas and let Lens suggest a chart type.
- Save to the dashboard, and set the dashboard's default time range.
- Export the finished dashboard to git with saved objects export.
Example: OPNsense NIC link state¶
OPNsense logs interface flaps from the kernel as lines like:
kernel: igb0: link state changed to DOWN
Parse it¶
Add a processor to the OPNsense ingest pipeline after the main grok:
{
"grok": {
"field": "_tmp.msg",
"if": "ctx.process?.name == 'kernel'",
"patterns": ["%{DATA:observer.ingress.interface.name}: link state changed to %{WORD:opnsense.link_state}"],
"ignore_failure": true
}
}
Add opnsense.link_state (keyword) to the index template mappings, then roll the data stream over.
Panels¶
| Panel | Lens setup |
|---|---|
| Link changes over time | Bar, vertical stacked. X: @timestamp. Y: count. Breakdown: opnsense.link_state. Filter: opnsense.link_state : * |
| Flaps per interface | Table. Rows: observer.ingress.interface.name. Metric: count where opnsense.link_state : "DOWN" |
| Current state | Table. Rows: interface. Metric: Last value of opnsense.link_state sorted by @timestamp |
Alert on it¶
In Stack Management → Rules, create an Elasticsearch query rule with opnsense.link_state : "DOWN" over the last 5 minutes and a threshold of count above 0.