1
2
mirror of https://github.com/vimagick/dockerfiles synced 2024-07-03 00:33:55 +00:00
dockerfiles/elastalert/data/rules/example.yaml

30 lines
561 B
YAML
Raw Normal View History

2019-10-30 12:04:37 +00:00
name: example rule
2019-11-01 01:14:24 +00:00
is_enabled: true
2019-10-30 08:11:49 +00:00
es_host: elasticsearch
es_port: 9200
type: frequency
index: logstash-*
2019-10-30 10:57:53 +00:00
doc_type: _doc
use_count_query: true
2019-10-30 12:04:37 +00:00
num_events: 10
2019-10-30 10:57:53 +00:00
2019-10-30 08:11:49 +00:00
timeframe:
2019-10-30 15:40:46 +00:00
minutes: 5
realert:
minutes: 60
2019-10-30 08:11:49 +00:00
filter:
- query:
query_string:
query: 'response:[500 TO *]'
alert:
2019-10-30 15:40:46 +00:00
- command:
command: [echo, bad, things, happen]
2019-10-30 12:04:37 +00:00
- slack:
slack_webhook_url: https://hooks.slack.com/services/XXXXXXXXX/XXXXXXXXX/XXXXXXXXXXXXXXXXXXXXXXXX
slack_username_override: ElastAlert
slack_channel_override: '#monit'
slack_emoji_override: ':bell:'