As highlighted in Chapter 10, Monitoring and Troubleshooting - Running a healthy OpenStack cluster, log files construct the best place to find clues about root causes for any issue. As we now have a better way to collect and parse OpenStack log files, if the monitoring server raises an alert for a specific OpenStack service host, an administrator can quickly start a custom query in Kibana and check the correspondent event during that given time. If the same alert occurs on more than one occasion, the search query can be saved and operators could decide, based on the issue frequency, to make any further design or configuration changes for a specific OpenStack component.
As the OpenStack log data is being shipped ...