The task of centralized management of logs in the network of situation centers of public author-ities and approaches to prototyping its software solution

V.A. Lytvynov, O.M. Myakshylo, V.O. Bratskyi
{"title":"The task of centralized management of logs in the network of situation centers of public author-ities and approaches to prototyping its software solution","authors":"V.A. Lytvynov, O.M. Myakshylo, V.O. Bratskyi","doi":"10.34121/1028-9763-2023-4-33-42","DOIUrl":null,"url":null,"abstract":"Event logging in distributed systems is one of the most important factors for ensuring proper monitoring and management of IT systems, and the use of log information is an important area of activity of DevOps and DevSecOps teams that ensure effective interaction between develop-ers, testers, and IT security professionals. The article discusses some possible approaches to prototyping solutions for the implementation of a centralized LMS (Log Management System) in the National Network of Situation Centers of Public Authorities (SCPA). As part of the first approach, which consists in the use of ready-made market products, a review of the declared capabilities, advantages, and disadvantages of popular free open-source systems and individual LMS tools (ELK Stack, Graylog, Grafana Loki, Logstash, Fluentd, LOGalyze, Filebeat, etc.) is carried out. In the context of the formulated basic requirements for a centralized LMS, taking into account the existing experience of using the tools under consideration, the expediency of choosing solutions among two complex, full-featured systems, namely the ELK Stack (Elas-ticsearch + Logstash + Kibana complex) and the complete, self-sufficient Graylog package, is substantiated. The advantages and disadvantages of each system are considered, and the gener-alized data on the implementation of ELK – Graylog, their use and evaluation by real users, formed on the basis of materials presented by the research company Gartner, are provided. An example of the possible implementation of the second approach to creating a prototype of LMS, which consists in creating new tools, is the developed specialized system for diagnosing errors registered in log files. The structure of the system, the functions of the main components, and the results of testing in a corporate banking network are described.","PeriodicalId":473328,"journal":{"name":"Matematičeskie mašiny i sistemy","volume":"56 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Matematičeskie mašiny i sistemy","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.34121/1028-9763-2023-4-33-42","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Event logging in distributed systems is one of the most important factors for ensuring proper monitoring and management of IT systems, and the use of log information is an important area of activity of DevOps and DevSecOps teams that ensure effective interaction between develop-ers, testers, and IT security professionals. The article discusses some possible approaches to prototyping solutions for the implementation of a centralized LMS (Log Management System) in the National Network of Situation Centers of Public Authorities (SCPA). As part of the first approach, which consists in the use of ready-made market products, a review of the declared capabilities, advantages, and disadvantages of popular free open-source systems and individual LMS tools (ELK Stack, Graylog, Grafana Loki, Logstash, Fluentd, LOGalyze, Filebeat, etc.) is carried out. In the context of the formulated basic requirements for a centralized LMS, taking into account the existing experience of using the tools under consideration, the expediency of choosing solutions among two complex, full-featured systems, namely the ELK Stack (Elas-ticsearch + Logstash + Kibana complex) and the complete, self-sufficient Graylog package, is substantiated. The advantages and disadvantages of each system are considered, and the gener-alized data on the implementation of ELK – Graylog, their use and evaluation by real users, formed on the basis of materials presented by the research company Gartner, are provided. An example of the possible implementation of the second approach to creating a prototype of LMS, which consists in creating new tools, is the developed specialized system for diagnosing errors registered in log files. The structure of the system, the functions of the main components, and the results of testing in a corporate banking network are described.
介绍了公共机关态势中心网络日志集中管理的任务及其软件解决方案的原型设计方法
分布式系统中的事件日志记录是确保适当监控和管理IT系统的最重要因素之一,日志信息的使用是DevOps和DevSecOps团队活动的一个重要领域,它确保了开发人员、测试人员和IT安全专业人员之间的有效交互。本文讨论了在国家公共权力机构情景中心网络(SCPA)中实现集中式LMS(日志管理系统)的原型解决方案的一些可能方法。作为第一种方法的一部分,包括使用现成的市场产品,对流行的免费开源系统和单个LMS工具(ELK Stack、Graylog、Grafana Loki、Logstash、Fluentd、LOGalyze、Filebeat等)的声明功能、优缺点进行了回顾。在集中式LMS制定基本需求的背景下,考虑到所考虑的工具的现有使用经验,在两个复杂的全功能系统(即ELK Stack (elasticsearch + Logstash + Kibana complex)和完整的、自给自足的Graylog包)中选择解决方案的便利性得到了证明。考虑了每个系统的优缺点,并根据研究公司Gartner提供的材料,提供了ELK - Graylog实施、实际用户使用和评估的一般数据。创建LMS原型的第二种方法(包括创建新工具)的可能实现示例是开发用于诊断日志文件中记录的错误的专用系统。介绍了系统的结构、主要组成部分的功能以及在企业银行网络中的测试结果。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信