Question

HowTo: Jsonify Looker Logs

  • 1 August 2016
  • 5 replies
  • 75 views

Hi all,


we use EBK (Elasticsearch, Beats + Kibana) and want to have the Looker logs in there as well. Since you can’t change the output format of Looker logs here is a small script to wrap the logs into a json structure.


https://gist.github.com/sisu-frank-kutzey/02d54375ae3aed6d393701ab9cbdf8c0


I’m pretty sure there can be some overflows since I don’t know all looker logs but it worked pretty good so far.

FYI: @maxcorbin


5 replies

Userlevel 3

@sisu_frank_kutzey,


This is pretty cool. Are y’all using this for analytics on top of Looker?

Hey,


we “just” use it to import the log data from Looker into Elasticsearch for monitoring.

Problem was that we use Beats and not Logstash so only json like logs can be processed.

Userlevel 3
Badge

This is super neat, thanks for sharing Frank!

This was super useful @sisu_frank_kutzey!


I made a slight modification to deal with the fact that some INFO messages can span multiple lines


https://gist.github.com/sisu-frank-kutzey/02d54375ae3aed6d393701ab9cbdf8c0#gistcomment-1964691

It just occurred to me to point out this: Looker logs can now be configured to output as JSON.
https://docs.looker.com/admin-options/server/log#setting_the_log_format_on_customer-hosted_instances

Reply