Files
pipistrello 1fb6899b1f DEPOT logging: add Telemt fleet monitoring via Zabbix
Install and persist Grafana Zabbix plugin 6.5.0, provision the internal Zabbix datasource, and add a fleet dashboard modeled on client 02 Telemt panels.

Add an active-agent Zabbix 7 template plus a 30-second sanitized collector for active IP count/list, connections, traffic, and uptime. Active checks avoid inbound polling of client-private Docker hosts.

The exact Zabbix host names and required ZABBIX_API_TOKEN Portainer variable are documented. Compose validation passed on 10.0.0.6; the live plugin registered successfully under Grafana 13.1.0.
2026-07-31 11:55:55 +03:00

53 lines
1.3 KiB
Plaintext

// Replaces Promtail in the old syslog-ng -> Promtail -> Loki path.
//
// DEPOT's fleet is not uniformly parseable as RFC3164: some RouterOS senders
// emit raw messages without a PRI/header. syslog-ng therefore keeps listening
// on the public stack ports and normalizes every message to RFC5424 before
// forwarding it here on the private stack network.
loki.relabel "syslog" {
forward_to = []
// Preserve the label used by the existing history and MikroTik dashboard.
rule {
source_labels = ["__syslog_message_hostname"]
target_label = "routerboard"
}
rule {
source_labels = ["__syslog_message_severity"]
target_label = "severity"
}
rule {
source_labels = ["__syslog_message_facility"]
target_label = "facility"
}
rule {
source_labels = ["__syslog_connection_ip_address"]
target_label = "source_ip"
}
}
loki.source.syslog "normalized_syslog" {
listener {
address = "0.0.0.0:1514"
protocol = "tcp"
syslog_format = "rfc5424"
labels = {
job = "syslog",
transport = "syslog-ng",
}
}
relabel_rules = loki.relabel.syslog.rules
forward_to = [loki.write.default.receiver]
}
loki.write "default" {
endpoint {
url = "http://loki:3100/loki/api/v1/push"
}
}