Diagnostics with Event Hub and ELK

Last updated: 29/08/2016

This template deploys an Elasticsearch cluster and Kibana and Logstash VMs. Logstash is configured with an input plugin to pull diagnostics data from Event Hub.

Parameter Name Description
esClusterName The name of the Elasticsearch cluster.
esVersion Elasticsearch version to install.
vmClientNodeCount Number of Elasticsearch client nodes to provision (Setting this to zero puts the data nodes on the load balancer)
vmDataNodeCount Number of Elasticsearch data nodes
vmSizeMasterNodes Size of the Elasticsearch cluster master nodes
vmSizeClientNodes Size of the Elasticsearch cluster client nodes
vmSizeDataNodes Size of the Elasticsearch cluster data nodes
adminUsername User name for the Virtual Machine.
adminPassword Password for the Virtual Machine.
ubuntuOSVersion The Ubuntu version for the VM. This will pick a fully patched image of this given Ubuntu version.
existingEHNamespace Existing Event Hub namespace.
existingEHSharedAccessKeyName Existing Event Hub shared access key name.
existingEHSharedAccessKey Existing Event Hub shared access key.
existingEHEntityPath Existing Event Hub entity path.
existingEHPartitions Existing Event Hub partitions.
_artifactsLocation Change this value to your repo name if deploying from a fork
_artifactsLocationSasToken Auto-generated token to access _artifactsLocation

Use the template

New-AzureRmResourceGroupDeployment -Name <deployment-name> -ResourceGroupName <resource-group-name> -TemplateUri https://raw.githubusercontent.com/azure/azure-quickstart-templates/master/diagnostics-eventhub-elk/azuredeploy.json
Command line
azure config mode arm
azure group deployment create <my-resource-group> <my-deployment-name> --template-uri https://raw.githubusercontent.com/azure/azure-quickstart-templates/master/diagnostics-eventhub-elk/azuredeploy.json
