Files
feedc0de df3743c9dc
Validate and deploy Elastic Stack / Validate manifests (push) Successful in 13s
Validate and deploy Elastic Stack / Deploy to Kubernetes (push) Successful in 26s
Install elastic to the cluster
2026-08-24 21:40:59 +02:00

133 lines
3.1 KiB
YAML

apiVersion: v1
kind: ConfigMap
metadata:
name: netflow-ilm-policy
namespace: elastic
labels:
app.kubernetes.io/name: netflow
app.kubernetes.io/part-of: elastic-stack
data:
policy.json: |
{
"policy": {
"phases": {
"hot": {
"actions": {
"rollover": {
"max_age": "1d",
"max_primary_shard_size": "30gb"
}
}
},
"delete": {
"min_age": "30d",
"actions": {
"delete": {}
}
}
}
}
}
---
apiVersion: beat.k8s.elastic.co/v1beta1
kind: Beat
metadata:
name: netflow
namespace: elastic
labels:
app.kubernetes.io/name: netflow
app.kubernetes.io/part-of: elastic-stack
spec:
type: filebeat
version: 9.5.2
image: docker.elastic.co/beats/filebeat-wolfi:9.5.2
elasticsearchRef:
name: elasticsearch
kibanaRef:
name: kibana
config:
filebeat.modules:
- module: netflow
log:
enabled: true
var:
netflow_host: 0.0.0.0
netflow_port: 2055
expiration_timeout: 30m
queue_size: 32768
internal_networks:
- private
processors:
- add_fields:
target: observer
fields:
name: newgw
vendor: MikroTik
product: RouterOS
type: firewall
setup.dashboards.enabled: true
setup.dashboards.retry.enabled: true
setup.dashboards.retry.interval: 10s
setup.dashboards.retry.maximum: 0
setup.ilm.enabled: true
setup.ilm.policy_name: netflow-30d
setup.ilm.policy_file: /usr/share/filebeat/ilm/policy.json
setup.ilm.overwrite: true
queue.mem.events: 16384
queue.mem.flush.min_events: 1024
queue.mem.flush.timeout: 1s
max_procs: 2
logging.level: info
deployment:
podTemplate:
metadata:
labels:
app.kubernetes.io/name: netflow
app.kubernetes.io/part-of: elastic-stack
spec:
terminationGracePeriodSeconds: 60
containers:
- name: filebeat
securityContext:
runAsUser: 0
ports:
- name: netflow
containerPort: 2055
protocol: UDP
resources:
requests:
cpu: 500m
memory: 1Gi
limits:
cpu: "2"
memory: 2Gi
volumeMounts:
- name: ilm-policy
mountPath: /usr/share/filebeat/ilm
readOnly: true
volumes:
- name: ilm-policy
configMap:
name: netflow-ilm-policy
---
apiVersion: v1
kind: Service
metadata:
name: netflow
namespace: elastic
labels:
app.kubernetes.io/name: netflow
app.kubernetes.io/part-of: elastic-stack
annotations:
metallb.io/loadBalancerIPs: "192.168.0.20"
spec:
type: LoadBalancer
externalTrafficPolicy: Local
selector:
beat.k8s.elastic.co/name: netflow
ports:
- name: netflow
port: 2055
targetPort: netflow
protocol: UDP