andromedarabbit
3/3/2017 - 3:44 PM

ElastAlert rule example

ElastAlert rule example

# Alert when the rate of events exceeds a threshold

# (Required)
# Rule name, must be unique
name: OutOfMemoryError

# (Required)
# Type of alert.
# the frequency rule type alerts when num_events events occur with timeframe time
type: frequency

# (Required)
# Index to search, wildcard supported
index: logstash-%Y.%m.%d*

use_strftime_index: true

# (Required, frequency specific)
# Alert when this many documents matching the query occur within a timeframe
num_events: 1

# (Required, frequency specific)
# num_events must occur within this amount of time to trigger an alert
timeframe:
  hours: 1

# (Required)
# A list of Elasticsearch filters used for find events
# These filters are joined with AND and nested in a filtered query
# For more info: http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/query-dsl.html
filter:
- query_string:
    query: "message: OutOfMemoryError OR log: OutOfMemoryError"

# (Required)
# The alert is use when a match is found
alert:
- "slack"