Service troubleshooting with Ascender Ledger Pro
Greg Sowell shows how Ascender Ledger Pro turns the flood of log data produced by AWX-derived platforms, including Ascender, Ansible Automation Platform, and Tower, into something you can actually troubleshoot with. The scenario is a Rocky Linux 8 server that has stopped sending syslog messages to its collector, and the question is what changed.
In the Services view, the Current tab lists the state of every known service on every host that Ledger Pro tracks through gather-services data. Filtering down to the one host and typing syslog reveals that the standard syslog service is stopped while rsyslog has been added, pointing to a misconfiguration when someone introduced the newer service. The Log tab then shows the date and time the service state changed, so the timestamp can be correlated with when messages stopped arriving at the collector. It is a short demo aimed at admins who want faster root-cause analysis across many hosts.
Key takeaways
- Ledger Pro ingests logs from any AWX derivative, including Ascender, Ansible Automation Platform, and Tower, and parses them into searchable data.
- The Services Current view shows the state of every service on every host, and a host filter narrows it to one server.
- Filtering on syslog reveals the syslog service stopped while rsyslog was added, suggesting a misconfiguration during the change.
- The Services Log tab records when each state change happened, so it can be correlated with when syslog messages stopped arriving.
Questions this video answers
How do you find out which service stopped on a host with Ascender Ledger Pro?
Open the Services section, choose Current, and filter by the host name to see every service on that machine along with its current state. Typing a service name such as syslog narrows the list further, showing in this case that syslog is stopped while rsyslog is running.
Can Ledger Pro tell you when a service changed state?
Yes. The Log view under Services keeps a running record of service changes, and searching for the service shows the date and time it stopped. That timestamp can be matched against when the syslog collector stopped receiving messages to confirm the cause.
About this video
When something suddenly stops working in your environment, it can be difficult to pinpoint the cause. Watch how Greg Sowell demonstrates service troubleshooting at lightning speed via Ledger Pro.
This video is part of the Ascender Pro playlist. Browse every CIQ video by product and topic.
Transcript
hey everybody I'm Greg Sowell and welcome to another ciq demo today I'm going to be showing you how to do some troubleshooting with a cinder Ledger Pro and in particular it's going to be service troubleshooting on your hosts while this is possible one because if you have an awx derivative so that's going to be your sender your AAP your tower all those various flavors they have the capability of creating a ton of log information while all that could get shipped off to a CER Ledger Pro and it can parse it and make it usable for you and so specifically my use case today is
I have a server it's a rocky 8 server and recently it stopped sending syis loog messages back to my syis loog collector now I need to troubleshoot what happened I'm going to click on Services over here I'm going to click on current and it will show me all of the services there State their status for every host I have in my environment well that's a little bit more than I actually need I really just need to filter it right so I'm going to filter down by host here in this example I'm going to start typing the name and it's nice enough to fill in the
blank for me there I'm going do my Rocky 8 server so I'm going to click that and now it's got all of the uh Services known just to that individual host and their current state because it's sending back U my sender is sending back uh gather Services inform information so I've got the the most recent version of what's going on in here so I'm going to type sis log and see ah well I see that uh one I have the CIS log.
service is stopped not found and I also have R CIS log so R CIS log is a more advanc version of syis loog added some um some bells and whistles in there while our our default is usually syis loog so I'm guessing when somebody made the modification added that additional system in there uh or rather service that they misconfigured something so let me see if I can go to the log section which keeps a running tally of when things actually changed in here you can see I have several in here but if I had a whole bunch of different change conditions I could just type
View full transcriptHide full transcript
CIS log again here in the search and I could see the date and time when that was actually stopped so it actually can help us narrow down does this correspond when uh with uh when we saw the CIS information stop coming into our our um our CIS log collector right so it can actually start doing some kind of information correlation in there so this was a quick hit I hope you can see how this can be useful in your environment especially when you're doing various troubleshooting tasks if you have any questions or comments and I'm assuming one of the questions is how do I get
a hold of Ledger Pro please feel free to reach out to us we love helping folks if you'd like to see different demos of different things reach out there we love feedback feedback on the video email call us I don't care just uh just let us know that you're out there and you're interested so if nothing else happy happy uh troubleshooting happy ledgering we'll see you next time bye
Built for scale. Chosen by the world’s best.
2.75M+
Rocky Linux instances
Being used world wide
90%
Of fortune 100 companies
Use CIQ supported technologies
250k
Avg. monthly downloads
Rocky Linux
9
Enterprise products
Spanning the kernel to the orchestrator
Have questions about your infrastructure?
Talk to a CIQ engineer about Rocky Linux, HPC, and AI infrastructure.
