Fleet Management Overview

The Fleet Overview page allows you to monitor the status of your fleet of Falcon Log Collector instances which have been either enrolled into Manage Remote Configurations Management and those which have been added to Fleet Management.

Manage Remote Configurations

Note

You can only see Falcon Log Collector instances which have been configured to work with Fleet Management.

Fleet Overview

Figure 8. Fleet Overview


Viewing the Status of your Fleet

You can achieve the following from Fleet overview:

  • see when data was last ingested.

  • see how much data was ingested in the last 24 hours.

  • see which instance have been enrolled in remote configuration management and their configurations.

  • view the status of an instance where; Okay means no errors has been reported and Error means an error is present and you can view details in a pop-up.

  1. Go to your LogScale account and click Data Ingest. The Fleet overview page will load with all the Falcon Log Collectors which have been configured for fleet management and/or enrolled in remote config file management.

  2. Click Fleet Overview on the left menu. The page will be displayed with the details listed above. You can use the filter boxes to filter by status and or the assigned configuration.

Switching between Live and Historic overview

The default overview is Live - meaning collectors that are online at the moment. The Live fleet overview will be continuously updated with e.g. Status updates or new CPU metrics.

When disabled the fleet overview will display all records of collectors for the last 30 days. In this case the overview will not be updated with the latest information.

Fleet Overview - Historic

Figure 9. Fleet Overview - Historic


Viewing Details on a Specific Instance

Search for specific instances and then view details on the host and logs.

  1. Go to Data ingest. The Fleet overview page will load with all the Falcon Log Collectors which have been configured for fleet management, see Fleet Management (fleetManagement) for more information.

  2. Click Fleet overview on the left menu.

  3. Search for the required instance by version, hostname or system, or use the filter boxes to filter by configuration and/or status. Click ... next to the instance.

    Fleet Overview Search

    Figure 10. Fleet Overview Search


  4. Click See more details and a pop-up is displayed with these details about the host, instance and the log sources:

    General

    • Hostname — The name of the host.

    • System — The operating system on which the instance is running.

    • Version — The version of Falcon Log Collector installed.

    • IP Address — The IP Address of the host.

    • Machine ID — Unique UUID generated on the host machine.

    • Ephemeral Timeout — If a collector is offline for the specified duration it will be unenrolled and disappear from the fleet overview.

    Log Sources

    • Source Name — The name of the source.

    • Source Type — The type of source, for example, syslog.

    • Repository — The name of the repository assigned to collect the data via token.

    • Parser — The name of the parser, if assigned.

    Metrics

    • Last activity— when the instance was last active.

    • ingest— the amount of data ingested in the last 24 hours.

    • CPU— the average CPU usage in the last 5 minutes.

    • disk— the max disk usage in the last 5 minutes.

    • memory— the max memory usage in the last 5 minutes.

    Config

    • Config name— the name of the configuration or configurations which are assigned to the instance.

    • Added by— the source of the configuration assignment, which can be manual or the name of the group.

    • Error messages— A list of error messages related to the configuration YAML, like duplicated sections..

    • Combined YAML— The full configuration of the collector.

    Instance Details Pop-up

    Figure 11. Instance Details Pop-up


    Instance Details Pop-up - Config

    Figure 12. Instance Details Pop-up - Config


Extending Remote Configurations

You can extend the group configuration which has been assigned to your Falcon Log Collector Instance through.

  1. Go to Data ingest tab and click Fleet overview.

  2. Click the ellipsis icon next to the instance you want to change and select Extend config.

  3. Select the configuration to add the configuration (combined or singular) from the drop down menu and click Save to confirm.