I have a question related to more static data for analytics and if anyone has any ideas for doing it with Graylog.
Let’s say I have a property like total System RAM that I want to pop into Graylog.
I’m not sure how I could do this and still have the data in Graylog be useful for analytics. I could import the data just once but that may be an issue if the index fills up and rotates, it would also be an issue if the data ever has to change.
I could just put a timestamp on it, import it at some frequency, and treat it like a normal log entry – but it doesn’t seem that I’ve got a way to query and say, “Give me only the most recent entry (or the entry that is closest to this time) that matches this query for each source” (something I may want to do if I wanted to know the average max ram across my fleet). This would give me a timelapse for a specific machine but doesn’t seem like it would be useful for analytics across the fleet.
I also cannot apply a time range to an entry to say this is the value for this range of time – I could then just write a query that says what is the value of the max ram in the log entries whose time ranges cover a specific time.
Is Graylog not the right tool for this? Is there anyway to get some of this functionality across a fleet versus just a timelapse for a specific endpoint?