<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Capture events from Opensearch and setup alerts in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/Capture-events-from-Opensearch-and-setup-alerts/m-p/972563#M30215</link>
    <description>&lt;P&gt;Gregg, thanks a lot for the link to display log messages to Grafana and also Grafana alerting .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regarding my original question (export the compute - programming container log), have deployed logging/monitoring a year ago when this was under github DAC, so not have the kubernetes github configured for our logging/monitoring.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in Dashboards, I filtered for this container and level,&amp;nbsp; I can export a page at a time, but was not able to export all the events since there are over 2000 pages after applying the filter criteria. is this possible?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your input!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Aug 2025 13:46:42 GMT</pubDate>
    <dc:creator>drahorg</dc:creator>
    <dc:date>2025-08-13T13:46:42Z</dc:date>
    <item>
      <title>Capture events from Opensearch and setup alerts</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Capture-events-from-Opensearch-and-setup-alerts/m-p/972356#M30201</link>
      <description>&lt;P&gt;We have deployed Viya 2024.09LTS, additionally logging and monitoring. I need to report on the events when a specific container got an error during the last 7 days. I know that in Opensearch - Dashboards - Log message with Level (Pods/container) - Filter for kube.container=ContainerName and level=error. I have 2 questions if you can help&lt;/P&gt;
&lt;P&gt;1. Since there are shown many thousands of pages of these results, how can I export all these to a large Excel or csv/text file so that is easier to filter and look at the results.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. is it possible to send any notifications/alerts when let's say a specific word appear in the message for this criteria (eg&amp;nbsp; Opensearch - Dashboards - Log message with Level (Pods/container) - Filter for kube.container=ContainerName and level=error. if the message contains failure then send an alert and or email). any alerting can be enabled and show in an alerts page?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot for your help!&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2025 19:56:53 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Capture-events-from-Opensearch-and-setup-alerts/m-p/972356#M30201</guid>
      <dc:creator>drahorg</dc:creator>
      <dc:date>2025-08-08T19:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: Capture events from Opensearch and setup alerts</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Capture-events-from-Opensearch-and-setup-alerts/m-p/972434#M30206</link>
      <description>The getlogs.py in viya4-monitoring-kubernetes/logging/bin is the easiest way (in my opinion) to pull the relevant lines out. &lt;BR /&gt;./getlogs.py -fo csv -l ERROR -c &amp;lt;container-name&amp;gt; -m 10000 -o errors.csv -st 2025-08-04 00:00:00 (7 days ago)&lt;BR /&gt;You can also export the results using opensearch dashboards.&lt;BR /&gt;&lt;BR /&gt;For alerting you would need to use Grafana, which I think would require configuring OpenSearch as a data source for Grafana.&lt;BR /&gt;&lt;BR /&gt;Display Log Messages in Grafana Dashboards&lt;BR /&gt;&lt;A href="https://go.documentation.sas.com/doc/en/obsrvcdc/v_003/obsrvdply/p1bqqaa7r8s06jn1pjexe3ymrckn.htm" target="_blank"&gt;https://go.documentation.sas.com/doc/en/obsrvcdc/v_003/obsrvdply/p1bqqaa7r8s06jn1pjexe3ymrckn.htm&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;You could then build alerts based using the datasource.&lt;BR /&gt;&lt;BR /&gt;Manage Grafana Alerting&lt;BR /&gt;&lt;A href="https://go.documentation.sas.com/doc/en/obsrvcdc/v_003/obsrvug/n1eslak1oy1dq4n1d9nbtuqefwpb.htm" target="_blank"&gt;https://go.documentation.sas.com/doc/en/obsrvcdc/v_003/obsrvug/n1eslak1oy1dq4n1d9nbtuqefwpb.htm&lt;/A&gt;</description>
      <pubDate>Mon, 11 Aug 2025 13:38:03 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Capture-events-from-Opensearch-and-setup-alerts/m-p/972434#M30206</guid>
      <dc:creator>gwootton</dc:creator>
      <dc:date>2025-08-11T13:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: Capture events from Opensearch and setup alerts</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Capture-events-from-Opensearch-and-setup-alerts/m-p/972563#M30215</link>
      <description>&lt;P&gt;Gregg, thanks a lot for the link to display log messages to Grafana and also Grafana alerting .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regarding my original question (export the compute - programming container log), have deployed logging/monitoring a year ago when this was under github DAC, so not have the kubernetes github configured for our logging/monitoring.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in Dashboards, I filtered for this container and level,&amp;nbsp; I can export a page at a time, but was not able to export all the events since there are over 2000 pages after applying the filter criteria. is this possible?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your input!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Aug 2025 13:46:42 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Capture-events-from-Opensearch-and-setup-alerts/m-p/972563#M30215</guid>
      <dc:creator>drahorg</dc:creator>
      <dc:date>2025-08-13T13:46:42Z</dc:date>
    </item>
    <item>
      <title>Re: Capture events from Opensearch and setup alerts</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Capture-events-from-Opensearch-and-setup-alerts/m-p/972567#M30217</link>
      <description>I believe both the OpenSearch Dashboards UI and python script have a limit of 10,000 records you can export at a time.</description>
      <pubDate>Wed, 13 Aug 2025 15:24:03 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Capture-events-from-Opensearch-and-setup-alerts/m-p/972567#M30217</guid>
      <dc:creator>gwootton</dc:creator>
      <dc:date>2025-08-13T15:24:03Z</dc:date>
    </item>
  </channel>
</rss>

