-
Notifications
You must be signed in to change notification settings - Fork 14
Home
Welcome to the squid-filebeat-kibana wiki!
-
Go to "Visualisations" and "Create new visualisations"
-
Pick "Coordinate Map" from the list
-
At step "Choose a source" change "type" to "Index pattern" and click on "filebeat-*" (it can be also "Saved search" and "Squid3 Proxy Access" if exists)
-
At Data tab under "Buckets" click "Add" and choose "Geo coordinates" and then "Geohash" as aggregation.
-
At "Field" click on drop down menu and start typing "squid.access.geoip.location" (if that value is not available it means that index has no required mapping. Only fields with "geo_point" type a visible here)
-
At the top right corner change time to the time range where records are expected and run "Update". (e.g. Last 24 hours)
-
Click play icon "Apply changes".
-
If color circles showed up then on the left top corner click "Save", provide title "SQUID_DST" and click on "Confirm Save"
-
Go to the Squid dashboard and check if map is there. If not - edit, delete from the dashboard old reference and add newly created "SQUID_DST". Save the dashboard at the end.