Andrew Mercer
on this page

General workflow

  1. Data view first: in Stack Management → Data views, create one for the data stream (for example logs-opnsense-*, time field @timestamp).
  2. Explore in Discover: narrow the query until the documents are the ones the panel should show.
  3. Dashboards → Create → Create visualization opens Lens. Drag fields onto the canvas and let Lens suggest a chart type.
  4. Save to the dashboard, and set the dashboard's default time range.
  5. Export the finished dashboard to git with saved objects export.

OPNsense logs interface flaps from the kernel as lines like:

kernel: igb0: link state changed to DOWN

Parse it

Add a processor to the OPNsense ingest pipeline after the main grok:

{
  "grok": {
    "field": "_tmp.msg",
    "if": "ctx.process?.name == 'kernel'",
    "patterns": ["%{DATA:observer.ingress.interface.name}: link state changed to %{WORD:opnsense.link_state}"],
    "ignore_failure": true
  }
}

Add opnsense.link_state (keyword) to the index template mappings, then roll the data stream over.

Panels

Panel Lens setup
Link changes over time Bar, vertical stacked. X: @timestamp. Y: count. Breakdown: opnsense.link_state. Filter: opnsense.link_state : *
Flaps per interface Table. Rows: observer.ingress.interface.name. Metric: count where opnsense.link_state : "DOWN"
Current state Table. Rows: interface. Metric: Last value of opnsense.link_state sorted by @timestamp

Alert on it

In Stack Management → Rules, create an Elasticsearch query rule with opnsense.link_state : "DOWN" over the last 5 minutes and a threshold of count above 0.