You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Description
Look at gains from using centralized ELK logging from FCE
Who the primary contacts are for this work
Brett H (ICT)
Additional context or information
This backlog item was raised in response to presentation to ICT town hall on 2nd February - see Rich L, (Friday, 12 February 2021 at 12:22) Subject: FW: Recording was Re: Todays Town Hall
Brett H wrote (Monday, 15 February 2021 at 09:25) Abridged
The centralised elk does have the disadvantage that we can't give the manage_index_templates permission to users (because it's per-cluster, so you could theoretically change anyone's templates), so if you have frequently changing templates, it may not be the best answer.
Find out if there are limits on the amount of logging allowed - we are worried we might flood it
pjvv
changed the title
GPL-892 Look at gains from using centralized ELK logging from FCE
GPL-892 Look at gains from using centralized ELK logging from FCE (C=M,V=2*)
Jun 23, 2021
We cannot give manage_index_templates role to the user coz it has very broad access (like template delete privileges). Our requirement is the user needs to list the available template using "indices:admin/template/get".
Description
Look at gains from using centralized ELK logging from FCE
Who the primary contacts are for this work
Brett H (ICT)
Additional context or information
This backlog item was raised in response to presentation to ICT town hall on 2nd February - see Rich L, (Friday, 12 February 2021 at 12:22) Subject: FW: Recording was Re: Todays Town Hall
Brett H wrote (Monday, 15 February 2021 at 09:25) Abridged
See; https://ssg-confluence.internal.sanger.ac.uk/display/OPENSTACK/Using+ELK+to+centralise+logging
Gains
Costs
The centralised elk does have the disadvantage that we can't give the manage_index_templates permission to users (because it's per-cluster, so you could theoretically change anyone's templates), so if you have frequently changing templates, it may not be the best answer.
I did report this to elastic last year, but it's had very little movement: elastic/elasticsearch#53110
Questions
The text was updated successfully, but these errors were encountered: