Viewing the Results
Now that we've created the Pipeline that will generate our metrics, we need to change the collector such that it uses the new Pipeline instead of the passthru
Pipeline.
- Click the
Cribl
upper tab to go back to Stream. - With
Manage
active in Stream's top nav, selectData
and clickSources
. - Click on
S3
in theCollectors
section. - Expand the
pan-logs
collector by clicking on it. - In the
Result Settings
>Result Routing
section, change thePipeline
field to usefirewall_metrics
, and clickSave
.
That section should now look like this:
Now all that's left is to run the collector job and look at our results. In this case, unlike our earlier job, we actually want to collect all of the data in the archive bucket.
- Click the
Run
button next to your collector, and theRun configuration
modal will appear. - Click the
Full Run
selection, leave everything else as the default, and clickRun
. The modal should look like this:
If you click Stream's Monitoring
tab, hover over the System
menu, and then click Jobs
in resulting submenu, you can monitor the the data collection, like this:
The full job is likely to take about 15 minutes to run, but you can see results after a couple minutes. Here's how:
- Click the
Kibana - Dashboard
upper tab. - On the Dashboard, click the
Refresh
button.
Once the screen has refreshed, the visualizations should now have data in them, and look something like this: