更新时间:2024-07-25 GMT+08:00
分享

ER仪表盘模板

企业路由器(Enterprise Router, ER)可以连接虚拟私有云(Virtual Private Cloud, VPC)或本地网络来构建中心辐射型组网,是云上大规格、高带宽、高性能的集中路由器。企业路由器使用边界网关协议(Border Gateway Protocol, BGP),支持路由学习、动态选路以及链路切换,极大的提升网络的可扩展性及运维效率,从而保证业务的连续性。

云日志服务支持日志采集向导一站式采集ER日志,支持多维度分析,并为ER日志配置结构化和仪表盘。该仪表盘主要展示ER日志的TOP20包数统计、TOP20流量统计、流日志条数等信息。

前提条件

ER流量日志中心

  1. 登录云日志服务控制台。
  2. 在左侧导航栏中选择“仪表盘 ”。
  3. 在仪表盘模板下方,选择“ER仪表盘模板 > ER流量日志中心”,查看图表详情。

    • 过滤实例ID图,所关联的查询分析语句如下所示:
      SELECT DISTINCT(instance_id)
    • 过滤连接ID图,所关联的查询分析语句如下所示:
      SELECT DISTINCT(resource_id)
    • 流量方向图展示为静态过滤器,可按照入方向和出方向的流量进行过滤,所关联的查询分析语句如下所示:
    • 过滤源IP图,所关联的查询分析语句如下所示:
      SELECT DISTINCT(srcaddr)
    • 过滤目的IP图,所关联的查询分析语句如下所示:
      SELECT DISTINCT(dstaddr)
    • 过滤协议类型图,所关联的查询分析语句如下所示:
      SELECT DISTINCT(protocol)
    • TOP20包数统计图表所关联的查询分析语句如下所示:
      SELECT "srcaddr" as "源地址", "dstaddr" as "目的地址",  sum("packets") as "包数", "resource_id" as "连接ID", "instance_id" as "实例ID" group by "instance_id", "resource_id", "srcaddr", "dstaddr" order by "包数" desc limit 20
    • TOP20流量统计图表所关联的查询分析语句如下所示:
      SELECT "srcaddr" as "源地址", "dstaddr" as "目的地址",  sum("bytes") as "字节数", "resource_id" as "连接ID", "instance_id" as "实例ID" group by "instance_id", "resource_id", "srcaddr", "dstaddr" order by "字节数" desc limit 20
    • 流日志条数图表所关联的查询分析语句如下所示:
      select time_series(__time, 'PT1H', 'yyyy-MM-dd HH:mm:ss', '0', '+08:00') as "时间", count(*) as "流日志条数" group by "时间" order by "时间"
    • 流日志详情图表所关联的查询分析语句如下所示:
      SELECT "instance_id" as "实例ID", "resource_id" as "连接ID", "project_id" as "项目ID", "srcaddr" as "源IP", "dstaddr" as "目的IP", "srcport" as "源端口",  "dstport" as "目的端口", "protocol" as "协议类型", "direct" as "流量方向", "packets" as "包数", "bytes" as "字节数",  TIME_FORMAT( MILLIS_TO_TIMESTAMP("start"*1000), 'yyyy-MM-dd HH:mm:ss', '+08:00') as "开始时间", TIME_FORMAT( MILLIS_TO_TIMESTAMP("end"*1000) , 'yyyy-MM-dd HH:mm:ss', '+08:00') as "结束时间"

相关文档