
IBM Operations Analytics

Installing IBM Operations Analytics - Log Analysis Entry Edition 1.3.2 to analyse access logs from two http servers in load balancing.

By Kostas Koutsogiannopoulos


Log Analysis requires Red Hat Enterprise (RHEL) for Linux version 5, 6, or 7 or SUSE Linux Enterprise Server (SLES) version 11. So we are using again linux containers to setup our environment in SLES 11.4. We begin cloning a sles template:

# lxc-clone sles laserver
Created container laserver as copy of sles

After creation we configure our container's config file (/var/lib/lxc/laserver/config) to match our network settings. After boot we are using "yast" to upgrade the operating system.


For installing the product we need the following package:


We also need a user (other than root) in order to install the product, so we create "loguser" with yast. Then we can extract the package and run as loguser.

loguser@laserver:~> /IBM_packages/

For our installation we are using logstash to ingest the server with log records from multiple machines. So we dont need ITM Log File Agent to be installed as you can see to screenshots:

After that the Log analysis server is up 'n running.

Installing a custom Insight Pack

Lets say that our log files are using a custom format that is not covered from the product out of the box. In this case we can create out own insight pack.

Extract the zip file <installation home>/unity_content/tools/ in a temporary directory and cd to this directory.

Create a file "" to describe your custom log record. For example for our custom apache access logs we are using this .properties file:

username: unityadmin
password: unityadmin
scalaHome: /opt/IBM/LogAnalysis

delimiter: ,
moduleName: AccessLog_IA

name: logRecord
dataType: TEXT
retrievable: true
retrieveByDefault: true
sortable: false
filterable: false
searchable: true
path_1: content.text
combine: FIRST

name: request_id
retrievable: true
retrieveByDefault: true
sortable: true
filterable: false
searchable: true
dataType: TEXT

name: clientIP
retrievable: true
retrieveByDefault: true
sortable: true
filterable: true
searchable: true
dataType: TEXT

name: auth
retrievable: true
retrieveByDefault: true
sortable: true
filterable: true
searchable: true

dataType: TEXT
name: protocol
retrievable: true
retrieveByDefault: true
sortable: true
filterable: true
searchable: true
dataType: TEXT

name: timestamp
retrievable: true
retrieveByDefault: true
sortable: true
filterable: true
searchable: true
dataType: DATE
dateFormat: yyyy-MM-dd'T'HH:mm:ss

name: verb
retrievable: true
retrieveByDefault: true
sortable: true
filterable: true
searchable: true
dataType: TEXT

name: request_method
retrievable: true
retrieveByDefault: true
sortable: true
filterable: true
searchable: true
dataType: TEXT

name: request
retrievable: true
retrieveByDefault: true
sortable: true
filterable: false
searchable: true
dataType: TEXT

name: response
retrievable: true
retrieveByDefault: true
sortable: true
filterable: true
searchable: true
dataType: TEXT

name: bytes
retrievable: true
retrieveByDefault: true
sortable: true
filterable: false
searchable: false
dataType: LONG

name: referrer
retrievable: true
retrieveByDefault: true
sortable: true
filterable: true
searchable: true
dataType: TEXT

name: agent
retrievable: true
retrieveByDefault: true
sortable: true
filterable: true
searchable: true
searchable: true
dataType: TEXT

name: time_serve
retrievable: true
retrieveByDefault: true
sortable: true
filterable: false
searchable: true
dataType: TEXT

Then create your new insight pack using this command:

python ./ -u unityadmin -p unityadmin

The tool is creating a directory customLogsInsightPack_v1.1.0.0. In order to install this to server you need to zip it with the command:

zip customLogsaccessInsightPack_v1.1.0.0

Then install it with the following tool:

<installation home>/utilities/ -install <temporary directory>/

After that you can see your custom Source Types in your server's interface.

Installing logstash on a remote machine

IBM Log Analysis is supporting logstash 1.5.3. You can use the following compressed files in your server:

<installation home>/logstash-1.5.3/logstash-1.5.3.tar.gz
<installation home>/logstash-1.5.3/logstash-scala.tgz

Copy them to your remote machine and extract them.

You need to create a structure like this below to make logstash to work with scala plugin ingesting log records to your Log Analysis server:

<installation home>
| |_vendor
| |_lib
| | |_bootstrap
| | |_pluginmanager
| |_lin
| |_outputs

Inside the config directory edit logstash-scala.conf config file to match your log format and your servers settings.

Run logstash as agent with the following command:

<installation home>/logstash-1.5.3/logstash/bin/logstash agent --pluginpath <installation home>/logstash-1.5.3/logstash/outputs -f <installation home>/logstash-1.5.3/config/logstash-scala.conf

Usefull tools

Administer your server status:

<installation home>/utilities/ -stop
<installation home>/utilities/ -start
<installation home>/utilities/ -status

Monitor receiver's logs:

tail -f <installation home>/logs/GenericReceiver.log

Sample Dashboard

View epilis's profile on LinkedIn Visit us on facebook X epilis rss feed: Latest articles