mirror of
https://github.com/domainaware/parsedmarc.git
synced 2026-07-31 12:45:58 +00:00
date_range on ES/OpenSearch aggregate and SMTP TLS documents is a two-element array [begin, end]. A date histogram buckets a document once per value, so every over-time chart bucketing on date_range counted a report twice whenever its begin and end dates fell in different buckets. Range filtering on it was also wrong: a report spanning the whole window matches neither endpoint. Measured on the dev-stack sample data: a 1d histogram on date_range returns doc_count 4592 / message sum 4724 against true totals of 2300 / 2427; the same histogram on date_begin returns exactly 2300 / 2427. All date histograms (2 OSD/Kibana visualizations, 10 Grafana ES panels including the summary pies) and all time-range filters (24 Grafana target timeFields, the dmarc_aggregate* and smtp_tls* index-pattern timeFieldName, the dev-stack dmarc-ag datasource) now use the single-valued date_begin, matching the report-begin semantics of the PostgreSQL (begin_date) and Splunk (_time = interval begin) dashboards. Failure-report panels already used the single-valued arrival_date and are unchanged. Dev stack: installing the Elasticsearch datasource plugin via GF_INSTALL_PLUGINS crash-loops Grafana >= 13 (the image ships a root-owned plugins-bundled/elasticsearch remnant the background installer cannot replace), so the bootstrap script now installs it via grafana cli and restarts Grafana instead. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
75 lines
2.2 KiB
YAML
75 lines
2.2 KiB
YAML
name: parsedmarc-dashboards
|
|
|
|
include:
|
|
- docker-compose.yml
|
|
|
|
services:
|
|
kibana:
|
|
image: docker.elastic.co/kibana/kibana:8.19.7
|
|
environment:
|
|
- ELASTICSEARCH_HOSTS=http://elasticsearch:9200
|
|
ports:
|
|
- "127.0.0.1:5601:5601"
|
|
depends_on:
|
|
elasticsearch:
|
|
condition: service_healthy
|
|
|
|
opensearch-dashboards:
|
|
image: opensearchproject/opensearch-dashboards:3
|
|
environment:
|
|
- OPENSEARCH_HOSTS=["https://opensearch:9200"]
|
|
ports:
|
|
- "127.0.0.1:5602:5601"
|
|
depends_on:
|
|
opensearch:
|
|
condition: service_healthy
|
|
|
|
grafana:
|
|
image: grafana/grafana:latest
|
|
environment:
|
|
# Grafana reads GF_SECURITY_ADMIN_PASSWORD, not GRAFANA_PASSWORD. Default
|
|
# to "admin" so the login matches the bootstrap script's GRAFANA_PASSWORD
|
|
# default; set GRAFANA_PASSWORD in .env to change both in lockstep.
|
|
- GF_SECURITY_ADMIN_PASSWORD=${GRAFANA_PASSWORD:-admin}
|
|
# Grafana >= 13 no longer bundles the Elasticsearch datasource, but
|
|
# installing it via GF_INSTALL_PLUGINS crash-loops: the image ships a
|
|
# root-owned plugins-bundled/elasticsearch remnant the installer cannot
|
|
# replace. The bootstrap script installs it via `grafana cli` instead.
|
|
- GF_INSTALL_PLUGINS=grafana-piechart-panel,grafana-worldmap-panel
|
|
ports:
|
|
- "127.0.0.1:3000:3000"
|
|
depends_on:
|
|
elasticsearch:
|
|
condition: service_healthy
|
|
postgresql:
|
|
condition: service_healthy
|
|
|
|
postgresql:
|
|
image: postgres:17
|
|
environment:
|
|
- POSTGRES_USER=${POSTGRESQL_USER:-parsedmarc}
|
|
- POSTGRES_PASSWORD=${POSTGRESQL_PASSWORD:-parsedmarc}
|
|
- POSTGRES_DB=${POSTGRESQL_DB:-parsedmarc}
|
|
ports:
|
|
- "127.0.0.1:5432:5432"
|
|
healthcheck:
|
|
test:
|
|
[
|
|
"CMD-SHELL",
|
|
"pg_isready -U ${POSTGRESQL_USER:-parsedmarc} -d ${POSTGRESQL_DB:-parsedmarc}"
|
|
]
|
|
interval: 5s
|
|
timeout: 5s
|
|
retries: 20
|
|
|
|
splunk:
|
|
image: splunk/splunk:latest
|
|
environment:
|
|
- SPLUNK_START_ARGS=--accept-license
|
|
- "SPLUNK_GENERAL_TERMS=--accept-sgt-current-at-splunk-com"
|
|
- SPLUNK_PASSWORD=${SPLUNK_PASSWORD}
|
|
- SPLUNK_HEC_TOKEN=${SPLUNK_HEC_TOKEN}
|
|
ports:
|
|
- "127.0.0.1:8000:8000"
|
|
- "127.0.0.1:8088:8088"
|