Table of contents

How logging works on GOV.UK

Logit

GOV.UK is following The GDS Way guidance on logging by using the approved vendor Logit.

For information on how to log in and view stacks, please see the GOV.UK Logit documentation.

Filebeat

Each machine runs Elastic Filebeat, and indepedently ships logs to the Logit provided logstash endpoint.

Filebeat tails logs and can output to a variety of sources. It is fully incorporated into the Elastic ecosystem.

We use the filebeat::prospector defined type to create the filebeat configuration on each instance.

Logstream and Logship

We have a defined type in our Puppet code which uses logship to tail logfiles.

We only use Logstream to send nginx metrics, via statsd, to Graphite.

In the future this will be replaced.

Kibana

Kibana is the interface for viewing logs in Elasticsearch. Use the Logit interface to login to Kibana.

There’s some documentation on useful Kibana queries for 2nd line.

This page is owned by #2ndline and needs to be reviewed