View a markdown version of this page

Amazon OpenSearch Service のマネージド Prometheus コレクターを設定する - Amazon Managed Service for Prometheus

翻訳は機械翻訳により提供されています。提供された翻訳内容と英語版の間で齟齬、不一致または矛盾がある場合、英語版が優先します。

Amazon OpenSearch Service のマネージド Prometheus コレクターを設定する

Amazon OpenSearch Service 用 Amazon Managed Service for Prometheus マネージドコレクターは、OpenSearch Service ドメインから Prometheus 互換メトリクスを自動的にスクレイプし、送信先に転送します。Amazon Managed Service for Prometheus はコレクターを管理し、インスタンス、エージェント、スクレイパーを自分で管理することなく、必要なスケーラビリティ、セキュリティ、信頼性を提供します。送信先は、Amazon Managed Service for Prometheus ワークスペースまたは Amazon CloudWatch です。

Amazon Elastic Kubernetes Service または Amazon Managed Streaming for Apache Kafka と統合するスクレイパーを作成することもできます。詳細については、「Amazon EKS の統合」および「Amazon MSK の統合」を参照してください。

スクレイパーの作成

この手順では、Amazon OpenSearch Service ドメイン管理と Amazon Virtual Private Cloud ネットワーキングの概念に精通していることを前提としています。

OpenSearch Service ドメインのスクレイパーを作成するには、いくつかの前提条件があります。

  • Amazon Virtual Private Cloud アクセスを持つ Amazon OpenSearch Service ドメイン。マネージドコレクターは、VPC アクセスを持つ OpenSearch Service ドメインのみをサポートします。パブリックアクセスを備えたドメインはサポートされていません。

  • マネージドコレクターが HTTPS (ポート 443) 経由で OpenSearch Service ドメインエンドポイントに到達できるようにするセキュリティグループ。ドメインのセキュリティグループに、コレクター用に指定したセキュリティグループからの HTTPS トラフィックを許可するインバウンドルールを追加します。

収集する OpenSearch Service ドメインをスクレイパーに指示するには、リクエストの exportersフィールドにドメインを指定します。exporters フィールドはエクスポーター設定のリストを取得します。OpenSearch Service ドメインの場合は、ドメインdomainArnの openSearchConfigurationを に提供します。次の例に示すように、 sourceフィールドにネットワーク (サブネットとセキュリティグループ) を個別に指定します。

注記

スクレイパーは、スクレイパーの作成時に解決されたドメインの VPC エンドポイントを使用します。ドメインを再作成する場合、新しいエンドポイントを取得するため、新しいスクレイパーを作成するか、UpdateScraper で既存のスクレイパーを更新してドメインから収集する必要があります。

スクレイパーの作成時にスクレイプ設定を指定します。マネージドコレクターは指定したドメインに接続してメトリクスを自動的に収集するので、設定内でスクレープターゲットを指定する必要はありません。設定には、scrape_configs が正確に job_name であるジョブがある opensearch-exporter セクションを含める必要があります。という名前のジョブを含まない設定opensearch-exporterは拒否されます。スクレイプ設定を使用してスクレイプ間隔を設定し、オプションで収集したメトリクスをフィルタリングまたは再ラベル付けします。スクレイプ設定の例を次に示します。

global: external_labels: domain_name: my-opensearch-domain scrape_configs: - job_name: opensearch-exporter scrape_interval: 60s

サポートされているスクレイプ設定オプションの詳細については、「」を参照してくださいスクレイパー設定。

To create a scraper using the AWS API

CreateScraper API オペレーションを使用して、 AWS API でスクレイパーを作成します。次の例では、OpenSearch Service ドメインからメトリクスを収集し、Amazon Managed Service for Prometheus ワークスペースに送信するスクレイパーを米国東部 (バージニア北部) リージョンに作成します。サンプルコンテンツを独自のドメイン、ネットワーク、ワークスペース情報に置き換え、スクレイパー設定を指定します。

注記

OpenSearch Service ドメインの Amazon VPC と一致するようにセキュリティグループとサブネットを設定します。2 つのアベイラビリティーゾーンに少なくとも 2 つのサブネットを含めます。

POST /scrapers HTTP/1.1 { "alias": "myScraper", "source": { "vpcConfiguration": { "securityGroupIds": ["sg-security-group-id"], "subnetIds": ["subnet-subnet-id-1", "subnet-subnet-id-2"] } }, "exporters": [ { "openSearchConfiguration": { "domainArn": "arn:aws:es:us-east-1:123456789012:domain/my-opensearch-domain" } } ], "destination": { "ampConfiguration": { "workspaceArn": "arn:aws:aps:us-east-1:123456789012:workspace/ws-workspace-id" } }, "scrapeConfiguration": { "configurationBlob": "base64-encoded-blob" } }

Amazon Managed Service for Prometheus ワークスペースの代わりにメトリクスを Amazon CloudWatch に送信するには、 destinationを CloudWatch 設定に置き換えます。

"destination": { "cloudWatchConfiguration": { "datasetArn": "arn:aws:cloudwatch:us-east-1:123456789012:dataset/default" } }

scrapeConfiguration パラメータには、base64 でエンコードされた Prometheus 設定 YAML ファイルが必要です。次のいずれかのコマンドを実行して、YAML ファイルを base64 に変換します。任意のオンライン base64 コンバーターを使用してファイルを変換することもできます。

例 Linux/macOS
base64 -w0 scraper-config.yaml
例 Windows PowerShell
[Convert]::ToBase64String([System.IO.File]::ReadAllBytes("scraper-config.yaml"))
To create a scraper using the AWS CLI

create-scraper コマンドを使用して AWS Command Line Interfaceでスクレイパーを作成します。次の例のコマンドは、米国東部 (バージニア北部) リージョンにスクレイパーを作成します。サンプルコンテンツを独自のドメイン、ネットワーク、ワークスペース情報に置き換え、スクレイパー設定を指定します。

注記

OpenSearch Service ドメインの Amazon VPC と一致するようにセキュリティグループとサブネットを設定します。2 つのアベイラビリティーゾーンに少なくとも 2 つのサブネットを含めます。

aws amp create-scraper \ --source '{"vpcConfiguration":{"securityGroupIds":["sg-security-group-id"],"subnetIds":["subnet-subnet-id-1","subnet-subnet-id-2"]}}' \ --exporters '[{"openSearchConfiguration":{"domainArn":"arn:aws:es:us-east-1:123456789012:domain/my-opensearch-domain"}}]' \ --scrape-configuration configurationBlob=base64-encoded-blob \ --destination '{"ampConfiguration":{"workspaceArn":"arn:aws:aps:us-east-1:123456789012:workspace/ws-workspace-id"}}'
  • AWS API で使用できるスクレイパーオペレーションの完全なリストを次に示します。

    CreateScraper API オペレーションを使用してスクレイパーを作成します。

  • ListScrapers API オペレーションを使用して既存のスクレイパーを一覧表示します。

  • UpdateScraper API オペレーションを使用して、スクレイパーのエイリアス、設定、または送信先を更新します。

  • DeleteScraper API オペレーションを使用してスクレイパーを削除します。

  • DescribeScraper API オペレーションを使用してスクレイパーの詳細を取得します。

クロスアカウントの設定

クロスアカウント設定でスクレイパーを作成するには、メトリクスを収集する OpenSearch Service ドメインが Amazon Managed Service for Prometheus コレクターとは異なるアカウントにある場合、次の手順を使用します。

たとえば、OpenSearch Service ドメインaccount_id_sourceがあるソースアカウントと、Amazon Managed Service for Prometheus ワークスペースaccount_id_targetがあるターゲットアカウントの 2 つのアカウントがあるとします。

注記

次の手順の信頼ポリシーは、ARN によるスクレイパーを参照します。これには、スクレイパーを作成するまで存在しない scraper-id が含まれます。この順序付けの問題を回避するには、まず特定のスクレイパー ARN の代わりにワイルドカード (scraper/*) を使用してロールを作成し、スクレイパーを作成し、両方の信頼ポリシーを更新して、ワイルドカードを がCreateScraper返す実際のスクレイパー ARN に置き換えます。

クロスアカウント設定でスクレイパーを作成するには
  1. ソースアカウントで、ロール arn:aws:iam::111122223333:role/Source を作成し、次の信頼ポリシーを追加します。

    { "Effect": "Allow", "Principal": { "Service": [ "scraper.aps.amazonaws.com" ] }, "Action": "sts:AssumeRole", "Condition": { "ArnEquals": { "aws:SourceArn": "arn:aws:aps:aws-region:111122223333:scraper/scraper-id" }, "StringEquals": { "AWS:SourceAccount": "111122223333" } } }
  2. ターゲットアカウントで、ロールを作成し、次の信頼ポリシーarn:aws:iam::444455556666:role/Targetを追加します。これにより、ソースロールがロールを引き受けることができます。

    { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::111122223333:role/Source" }, "Action": "sts:AssumeRole", "Condition": { "StringEquals": { "sts:ExternalId": "arn:aws:aps:aws-region:111122223333:scraper/scraper-id" } } }

    送信先への書き込みを許可するアクセス許可ポリシーをターゲットロールにアタッチします。送信先が Amazon Managed Service for Prometheus ワークスペースの場合は、AmazonPrometheusRemoteWriteAccess ( を付与) をアタッチしますaps:RemoteWrite。送信先が Amazon CloudWatch の場合は、データセットcloudwatch:PutMetricDataに を付与するポリシーをアタッチします。

  3. --role-configuration オプションを使用してスクレイパーを作成します。

    aws amp create-scraper \ --source '{"vpcConfiguration":{"securityGroupIds":["sg-security-group-id"],"subnetIds":["subnet-subnet-id-1","subnet-subnet-id-2"]}}' \ --exporters '[{"openSearchConfiguration":{"domainArn":"arn:aws:es:aws-region:111122223333:domain/my-opensearch-domain"}}]' \ --scrape-configuration configurationBlob=<base64-encoded-blob> \ --destination '{"ampConfiguration":{"workspaceArn":"arn:aws:aps:aws-region:444455556666:workspace/ws-workspace-id"}}' \ --role-configuration '{"sourceRoleArn":"arn:aws:iam::111122223333:role/Source", "targetRoleArn":"arn:aws:iam::444455556666:role/Target"}'
  4. スクレイパーの作成を検証します。

    aws amp list-scrapers

スクレイパーの検出と削除

AWS API または を使用して AWS CLI 、アカウントのスクレイパーを一覧表示したり、削除したりできます。

注記

最新バージョンの AWS CLI または SDK を使用していることを確認します。最新バージョンには、最新の特長と機能に加え、セキュリティアップデートも含まれています。または、常に最新のコマンドラインエクスペリエンスを提供する AWS CloudShell を自動的に使用します。

アカウント内のすべてのスクレイパーを一覧表示するには、ListScrapers API オペレーションを使用します。または、 を使用して AWS CLIを呼び出します。

aws amp list-scrapers

スクレイパーを削除するには、ListScrapers オペレーションを使用して削除するスクレイパーの scraperId を見つけ、DeleteScraper オペレーションを使用して削除します。または、 を使用して AWS CLIを呼び出します。

aws amp delete-scraper --scraper-id scraperId

Amazon OpenSearch Service から収集されたメトリクス

Amazon OpenSearch Service と統合すると、Amazon Managed Service for Prometheus コレクターは、ドメインの状態とパフォーマンスを記述する Prometheus 互換メトリクスを自動的にスクレイプします。コレクターは数百のメトリクスを出力します。次の表は、各カテゴリの代表的なメトリクスを示しています。次の表のopensearch_indices_メトリクスはドメイン全体で集計され、多くの にはプライマリのみのバリアントと合計バリアント (サフィックス _primaryまたは ) があります_total。コレクターは、インデックス、プレフィックス 、opensearch_index_stats_およびプレフィックス のシャードごとのメトリクスごとに同じ統計も出力しますopensearch_indices_shards_。

メトリクス 説明/目的

opensearch_cluster_health_status

クラスターのヘルスステータス (緑、黄色、赤)。

opensearch_cluster_health_number_of_nodes

クラスター内のノードの数。

opensearch_cluster_health_number_of_data_nodes

クラスター内のデータノードの数。

opensearch_cluster_health_active_primary_shards

アクティブなプライマリシャードの数。

opensearch_cluster_health_active_shards

プライマリシャードとレプリカシャードを含むアクティブなシャードの合計数。

opensearch_cluster_health_relocating_shards

ノード間で再配置されるシャードの数。

opensearch_cluster_health_initializing_shards

初期化中のシャードの数。

opensearch_cluster_health_unassigned_shards

ノードに割り当てられていないシャードの数。

opensearch_cluster_health_delayed_unassigned_shards

割り当てが遅れる未割り当てのシャードの数。

opensearch_cluster_health_number_of_pending_tasks

キューに入れられ、実行を待っているクラスターレベルのタスクの数。

opensearch_cluster_health_number_of_in_flight_fetch

進行中のシャードフェッチリクエストの数。

opensearch_cluster_health_task_max_waiting_in_queue_millis

タスクがキューで待機した最長時間をミリ秒単位で表します。

メトリクス 説明/目的

opensearch_os_cpu_percent

ノード上のオペレーティングシステムが使用する CPU の割合。

opensearch_os_load1

過去 1 分間のオペレーティングシステムの負荷平均。コレクターは opensearch_os_load5と も出力しますopensearch_os_load15。

opensearch_os_mem_used_bytes

使用される物理メモリの量、バイト単位。コレクターは opensearch_os_mem_free_bytes、opensearch_os_mem_actual_used_bytes、および も出力しますopensearch_os_mem_actual_free_bytes。

opensearch_jvm_memory_used_bytes

メモリ領域別 (ヒープと非ヒープ) に使用される JVM メモリのバイト数。関連するメトリクスには、opensearch_jvm_memory_committed_bytes および opensearch_jvm_memory_max_bytes が含まれます。

opensearch_jvm_gc_collection_seconds_count

JVM ガベージコレクションイベントの総数。ガベージコレクションに費やされた合計時間opensearch_jvm_gc_collection_seconds_sumである で を使用します。

opensearch_jvm_uptime_seconds

JVM の稼働時間を秒単位で表します。

opensearch_thread_pool_active_count

各スレッドプール内のアクティブなスレッドの数。関連するメトリクスにはopensearch_thread_pool_queue_count、、opensearch_thread_pool_rejected_count、および が含まれますopensearch_thread_pool_completed_count。

opensearch_filesystem_data_available_bytes

ノードで使用可能なディスク容量、バイト単位。関連するメトリクスには、opensearch_filesystem_data_free_bytes および opensearch_filesystem_data_size_bytes が含まれます。

opensearch_filesystem_io_stats_device_read_operations_count

ディスク読み取りオペレーションの数。コレクターは、書き込みおよび合計オペレーション数、読み取りおよび書き込みサイズ ( など) も出力しますopensearch_filesystem_io_stats_device_read_size_kilobytes_sum。

opensearch_process_cpu_percent

OpenSearch プロセスで使用される CPU の割合。

opensearch_process_mem_resident_size_bytes

OpenSearch プロセスの常駐メモリサイズ、バイト単位。

opensearch_process_open_files_count

OpenSearch プロセスによって開いているファイル記述子の数。

opensearch_breakers_tripped

各サーキットブレーカーが作動した合計回数。関連するメトリクスには、opensearch_breakers_estimated_size_bytes および opensearch_breakers_limit_size_bytes が含まれます。

opensearch_transport_rx_size_bytes_total

ノード間のトランスポートレイヤーで受信したデータの合計量をバイト単位で表します。コレクターは opensearch_transport_tx_size_bytes_totalおよび パケット数も出力します。

opensearch_indexing_pressure_current_all_in_bytes

を設定した制限opensearch_indexing_pressure_limit_in_bytesとして、リクエストのインデックス作成によって消費される現在のメモリをバイト単位で指定します。

メトリクス 説明/目的

opensearch_indices_docs

ドキュメントの数。関連するメトリクスにはopensearch_indices_docs_deleted、、opensearch_indices_docs_primary、および が含まれますopensearch_indices_docs_total。

opensearch_indices_store_size_bytes

ディスク上のインデックスの合計サイズ、バイト単位、 opensearch_indices_store_size_bytes_primary および opensearch_indices_store_size_bytes_totalバリアント。

opensearch_indices_indexing_index_total

インデックスが作成されたドキュメントの合計数。インデックス作成のレイテンシーopensearch_indices_indexing_index_time_seconds_totalには、 で を使用します。

opensearch_indices_indexing_is_throttled

インデックス作成が現在スロットリングされているかどうかを示し、合計スロットリング時間opensearch_indices_indexing_throttle_time_seconds_totalに対して を使用します。

opensearch_indices_search_query_total

検索クエリの合計数。クエリのレイテンシーopensearch_indices_search_query_time_secondsには、 で を使用します。

opensearch_indices_search_fetch_total

フェッチレイテンシーopensearch_indices_search_fetch_time_secondsの を使用したフェッチオペレーションの合計数。

opensearch_indices_get_total

取得レイテンシーopensearch_indices_get_time_secondsの を含む取得オペレーションの合計数。

opensearch_indices_merges_total

完了したセグメントマージの合計数。関連するメトリクスには、opensearch_indices_merges_current および opensearch_indices_merges_total_time_seconds_total が含まれます。

opensearch_indices_refresh_total

インデックス更新オペレーションの総数。更新時間は opensearch_indices_refresh_time_seconds_totalです。

opensearch_indices_flush_total

インデックスフラッシュオペレーションの総数。フラッシュ時間は opensearch_indices_flush_time_secondsです。

opensearch_indices_segments_count

セグメントの数。コレクターは、セグメントごとのメモリメトリクス ( opensearch_indices_segments_memory_bytesや など) も出力しますopensearch_indices_segment_terms_memory_total。

opensearch_indices_translog_operations

トランザクションログ内のオペレーションの数。そのサイズopensearch_indices_translog_size_in_bytesには が付きます。

opensearch_indices_fielddata_memory_size_bytes

フィールドデータキャッシュがエビクションopensearch_indices_fielddata_evictionsに使用するバイト単位のメモリ。

opensearch_indices_query_cache_memory_size_bytes

クエリキャッシュで使用されるメモリ、バイト単位。関連するメトリクスには、opensearch_indices_query_cache_count および opensearch_indices_query_cache_evictions が含まれます。

opensearch_indices_request_cache_memory_size_bytes

リクエストキャッシュで使用されるメモリ、バイト単位。関連するメトリクスには、opensearch_indices_request_cache_count および opensearch_indices_request_cache_evictions が含まれます。

制限事項

Amazon OpenSearch Service と Amazon Managed Service for Prometheus の統合には、次の制限があります。

  • Amazon Virtual Private Cloud アクセスを持つ OpenSearch Service ドメインでのみサポートされます。パブリックアクセスを備えたドメインはサポートされていません。

  • スクレイパーは、単一の OpenSearch Service ドメインからメトリクスを収集します。複数のドメインからメトリクスを収集するには、各ドメインごとに個別のスクレイパーを作成します。