New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[ML] Adds ML jobs for access logs to Apache package #910
[ML] Adds ML jobs for access logs to Apache package #910
Conversation
💚 Build Succeeded
Expand to view the summary
Build stats
Test stats 🧪
Trends 🧪 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Please rebase it against master as I pushed fix for the missing spec (ML modules).
f3b0d67
to
60d52dd
Compare
60d52dd
to
dd59a6c
Compare
* [ML] Adds ML jobs for access logs to Apache package * Updates changelog to add entry for addition of ML jobs * Formatting fix for apache-Logs-ml.json
* [ML] Adds ML jobs for access logs to Apache package * Updates changelog to add entry for addition of ML jobs * Formatting fix for apache-Logs-ml.json
What does this PR do?
Adds an ML module containing anomaly detection jobs for finding unusual activity in HTTP access logs to the Apache integration. Requires Kibana 7.13.0 or later.
These are the same five jobs that have previously been stored inside the ML Kibana plugin:
Some minor edits have been made to the previous job configurations stored in the ML Kibana plugin:
apache_data_stream
compared toapache_ecs
for the legacy moduledata_stream.dataset: apache.access
compared toevent.dataset: apache.access
for the legacy moduleApache logs overview
dashboard which is already included in the Apache package.(ECS)
has been removed from the module and job description_apache
is appended to the IDs of the jobs in the modulecreated_by
property used for telemetry is set toml-module-apache-access-data-stream
compared toml-module-apache-access
for the legacy moduleChecklist
changelog.yml
file.How to test this PR locally
To test this PR:
logs-*
, matching the query in the ML module JSON file:logs-*
) and select the card for this new Apache access logs module:Related issues
elastic/package-spec#148
Screenshots
ML module is now listed in the Kibana assets section for the Apache package:
List of Apache jobs in the ML Job list:
Screenshot showing results of Apache ML jobs in the ML Anomaly Explorer: