mirror of
https://github.com/domainaware/parsedmarc.git
synced 2026-07-27 10:54:57 +00:00
The from-domain volume table on every provider's aggregate dashboard is now "Message volume and DMARC compliance by from domain" with columns From Domain | Messages | % DMARC Compliant: - OpenSearch Dashboards/Kibana: the agg-based data table is replaced by a TSVB table using a Filter Ratio metric (passed_dmarc:true over all, sum of message_count), pivoted on header_from.keyword. The time field is date_begin rather than the multi-valued date_range, which TSVB's per-value date histogram would double-count. Editing (not rendering) the panel on Kibana 8.x requires the metrics:allowStringIndices advanced setting. - Grafana (Elasticsearch): a second passed_dmarc:true query joined by field with a binary calculation (Sum 2 / Sum 1) rendered as percentunit. - Grafana (PostgreSQL): compliance column via an aggregate FILTER clause, COALESCEd so zero-pass domains show 0 instead of NULL. - Splunk: sum(eval(if(passed_dmarc="true", message_count, 0))) inside stats, per the SPL eval-in-stats syntax. All four providers were verified against the same seeded sample data in the dashboard dev stack; each returns identical per-domain values (example.com: 2425 messages, 5.3% compliant). Dev stack fixes found along the way: cap Elasticsearch heap at 2g (the unset heap auto-sized to 50% of host RAM and was OOM-killed with bootstrap.memory_lock on large hosts), and install the elasticsearch datasource plugin in Grafana, which is no longer bundled as of Grafana 13. Closes #112 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
73 lines
2.1 KiB
YAML
73 lines
2.1 KiB
YAML
name: parsedmarc-dashboards
|
|
|
|
include:
|
|
- docker-compose.yml
|
|
|
|
services:
|
|
kibana:
|
|
image: docker.elastic.co/kibana/kibana:8.19.7
|
|
environment:
|
|
- ELASTICSEARCH_HOSTS=http://elasticsearch:9200
|
|
ports:
|
|
- "127.0.0.1:5601:5601"
|
|
depends_on:
|
|
elasticsearch:
|
|
condition: service_healthy
|
|
|
|
opensearch-dashboards:
|
|
image: opensearchproject/opensearch-dashboards:3
|
|
environment:
|
|
- OPENSEARCH_HOSTS=["https://opensearch:9200"]
|
|
ports:
|
|
- "127.0.0.1:5602:5601"
|
|
depends_on:
|
|
opensearch:
|
|
condition: service_healthy
|
|
|
|
grafana:
|
|
image: grafana/grafana:latest
|
|
environment:
|
|
# Grafana reads GF_SECURITY_ADMIN_PASSWORD, not GRAFANA_PASSWORD. Default
|
|
# to "admin" so the login matches the bootstrap script's GRAFANA_PASSWORD
|
|
# default; set GRAFANA_PASSWORD in .env to change both in lockstep.
|
|
- GF_SECURITY_ADMIN_PASSWORD=${GRAFANA_PASSWORD:-admin}
|
|
# "elasticsearch" is required on Grafana >= 13, which no longer bundles
|
|
# the Elasticsearch datasource as a core plugin.
|
|
- GF_INSTALL_PLUGINS=grafana-piechart-panel,grafana-worldmap-panel,elasticsearch
|
|
ports:
|
|
- "127.0.0.1:3000:3000"
|
|
depends_on:
|
|
elasticsearch:
|
|
condition: service_healthy
|
|
postgresql:
|
|
condition: service_healthy
|
|
|
|
postgresql:
|
|
image: postgres:17
|
|
environment:
|
|
- POSTGRES_USER=${POSTGRESQL_USER:-parsedmarc}
|
|
- POSTGRES_PASSWORD=${POSTGRESQL_PASSWORD:-parsedmarc}
|
|
- POSTGRES_DB=${POSTGRESQL_DB:-parsedmarc}
|
|
ports:
|
|
- "127.0.0.1:5432:5432"
|
|
healthcheck:
|
|
test:
|
|
[
|
|
"CMD-SHELL",
|
|
"pg_isready -U ${POSTGRESQL_USER:-parsedmarc} -d ${POSTGRESQL_DB:-parsedmarc}"
|
|
]
|
|
interval: 5s
|
|
timeout: 5s
|
|
retries: 20
|
|
|
|
splunk:
|
|
image: splunk/splunk:latest
|
|
environment:
|
|
- SPLUNK_START_ARGS=--accept-license
|
|
- "SPLUNK_GENERAL_TERMS=--accept-sgt-current-at-splunk-com"
|
|
- SPLUNK_PASSWORD=${SPLUNK_PASSWORD}
|
|
- SPLUNK_HEC_TOKEN=${SPLUNK_HEC_TOKEN}
|
|
ports:
|
|
- "127.0.0.1:8000:8000"
|
|
- "127.0.0.1:8088:8088"
|