elastalert.py
SUMMARY
ENVIRONMENT
IMPORTANT NOTES
query_key: field_name.keyword metric_agg_key: field_name.keyword"log": ["log1.json", "log2.json", ...] or "log": "/dir"{ "total": 6, "pass": 3, "fail": 3, "tests": { "test_2": { "result": "PASSED", "message": [] }, "test_2": { "result": "PASSED", "message": [] }, "test_3": { "result": "FAILED", "message": [ "1 LOG(S) MATCHED: log001.json" ] }, "test_4": { "result": "FAILED", "message": [ "7 LOG(S) DID NOT MATCH: agg_log001.json, agg_log002.json, agg_log003.json, agg_log004.json, agg_log005.json, log001.json, log003.json" ] }, "test_agg_1": { "result": "FAILED", "message": [ "HITS (5) EXCEEDED THE THRESHOLD" ] } } }
SET-UP
EXECUTION (w/ sample output)
help (-h, --help)
-h, --help)default output
mappings (--mappings)
--mappings)> sample mappings.json
> execution
verbose (--verbose)
--verbose)Last updated