The following sections provide an overview of Azure ELK stacks and the ELK: Azure Activity Log PowerPack:
The ELK: Azure Activity Log PowerPack is meant to be used in conjunction with the Microsoft: Azure PowerPack. For more information about the Microsoft: Azure PowerPack, including how to install the PowerPack and discover Azure devices, see Monitoring Microsoft Azure.
What is an Azure ELK Stack?
An ELK stack is a centralized log management platform consisting of three open-source products:
- Elasticsearch, a storage solution with search and indexing capabilities
- Logstash, a server-side data collection engine
- Kibana, a web user interface used for visualizing stored data
In an ELK stack, Logstash collects data, Elasticsearch indexes and stores the data, and Kibana visually presents the data in a user-friendly manner.
You can install an ELK stack on a Microsoft Azure instance to collect, store, and visualize data about that instance.
What Does the ELK: Azure Activity Log PowerPack Monitor?
The ELK: Azure Activity Log PowerPack includes the following features:
- A sample Credential that you can use to create Basic/Snippet credentials to monitor Azure component devices in ELK stacks
- Dynamic Applications that align to Azure component devices in ELK stacks and then monitor Azure Activity Logs and state changes on Azure virtual machines
- An Event Policy that notifies users when the ELK Dynamic Applications have aligned to Azure components
- Run Book Policies and Actions that align the ELK Dynamic Applications to Azure components and update the alignment status on the ScienceLogic Data Collector or All-In-One Appliance
Installing the ELK: Azure Activity Log PowerPack
Before completing the steps in this
By default, installing a new version of a PowerPack overwrites all content from a previous version of that PowerPack that has already been installed on the target system. You can use the Enable Selective PowerPack Field Protection setting in the Behavior Settings page (System > Settings > Behavior) to prevent new PowerPacks from overwriting local changes for some commonly customized fields. For more information, see the section on Global Settings.
Ensure that you are running version 12.1.2 or later of SL1 before installing this PowerPack. For details on upgrading SL1, see the relevant SL1 Platform Release Notes.
To download and install the PowerPack:
- Search for and download the PowerPack from the PowerPacks page (Product Downloads > PowerPacks & SyncPacks) at the ScienceLogic Support Site.
- In SL1, go to the PowerPacks page (System > Manage > PowerPacks).
- Click the Import PowerPack. The Import PowerPack dialog box appears. button and choose
- Click [Browse] and navigate to the PowerPack file from step 1.
- Select the PowerPack file and click . The PowerPack Installer modal displays a list of the PowerPack contents.
- Click PowerPack is added to the PowerPacks page. . The
If you exit the PowerPack Installer modal without installing the imported PowerPack, the imported PowerPack will not appear in the PowerPacks page. However, the imported PowerPack will appear in the Imported PowerPacks modal. This page appears when you click the menu and select Install PowerPack.