mirror of
https://github.com/vimagick/dockerfiles.git
synced 2025-12-31 10:07:24 +01:00
update elastalert
This commit is contained in:
25
elastalert/data/rules/example.yaml
Normal file
25
elastalert/data/rules/example.yaml
Normal file
@@ -0,0 +1,25 @@
|
||||
name: Example rule
|
||||
|
||||
es_host: elasticsearch
|
||||
es_port: 9200
|
||||
|
||||
type: frequency
|
||||
|
||||
index: logstash-*
|
||||
|
||||
num_events: 10
|
||||
|
||||
timeframe:
|
||||
hours: 1
|
||||
|
||||
filter:
|
||||
- query:
|
||||
query_string:
|
||||
query: 'response:[500 TO *]'
|
||||
|
||||
alert:
|
||||
- command
|
||||
|
||||
command:
|
||||
- echo
|
||||
- "{match[@timestamp]} {match[message]}"
|
||||
Reference in New Issue
Block a user