Skip to content

Monitor the Sekoia.io Forwarder

The Sekoia.io Forwarder can send health metrics to a dedicated Sekoia intake. These metrics help you monitor resource usage, queue size, and message processing before a queue reaches capacity.

Prerequisites

Before you start, make sure that:

  • The Sekoia.io Forwarder is deployed. See Configure the Sekoia.io Forwarder.
  • You can create an intake in your Sekoia community.
  • You have access to the forwarder's intakes.yaml file.

Create the monitoring intake

Create a Sekoia.io forwarder logs intake in your community and copy its intake key. For details about the intake format, see Sekoia.io forwarder logs.

Enable metrics

  1. Open intakes.yaml.
  2. Add a monitoring entry with stats: True:

    ---
    intakes:
      - name: Monitoring
        stats: True
        intake_key: INTAKE_KEY_FOR_FORWARDER_LOGS
    
  3. Recreate the forwarder:

    sudo docker compose up -d
    

The monitoring intake does not require a port or protocol. The forwarder generates the metrics internally.

Monitor queue health

The forwarder uses the rsyslog impstats module to generate internal metrics for each configured intake. The metrics identify the intake that produced them.

The following detection rule pattern identifies full queues, which can cause event loss:

detection:
  selection:
    - sekoiaio.forwarder.queue.discarded.full|gt: 0
    - sekoiaio.forwarder.queue.discarded.nf|gt: 0
    - sekoiaio.forwarder.queue.full|gt: 0
  condition: selection

For the complete list of counters, see the rsyslog statistic counter documentation.

Retrieve metrics during an outage

If the forwarder cannot send metrics to Sekoia, it retains a raw copy inside the container. Copy the file to the host:

sudo docker compose cp rsyslog:/var/log/rsyslog-stats.log rsyslog-stats.log

Result

The forwarder sends its health metrics to the dedicated intake, where you can use them to monitor queue capacity and service interruptions.