As part of T287339: jupyter notebook causing syslog/etc.. to fill up with error messages a configuration change was made which should have caused Jupyter notebooks to be sent to our ELK+ system.
- A field of SyslogIdentifier=jupyterhub-conda-singleuser was added to the systemd service related to each user's notebook
- An entry for this programname was added to the file: /etc/rsyslog.lookup.d/lookup_table_output.json of the form: {"index" : "jupyterhub-conda-singleuser", "value" : "kafka" }
However the logs aren't yet appearing in Logstash, although I thought that this configuration would be all that was required.
As an aside, we submitted a patch to the systemdspawner (https://github.com/jupyterhub/systemdspawner/pull/83) which enables interpolation of {USERNAME} and {USERID} variables. This might be useful down the line in differentiating different users' notebooks from each other in Logstash.