{"id":40650,"date":"2023-08-06T22:58:12","date_gmt":"2023-08-11T22:56:12","guid":{"rendered":"https:\/\/www.silicloud.com\/zh\/blog\/%e8%b0%83%e6%9f%a5%e5%9f%ba%e4%ba%8eelasticsearch%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e8%ad%a6%e6%8a%a5%e9%80%9a%e7%9f%a5%e7%9a%84%e6%96%b9%e6%b3%95%e3%80%82\/"},"modified":"2024-04-30T17:19:03","modified_gmt":"2024-04-30T09:19:03","slug":"%e8%b0%83%e6%9f%a5%e5%9f%ba%e4%ba%8eelasticsearch%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e8%ad%a6%e6%8a%a5%e9%80%9a%e7%9f%a5%e7%9a%84%e6%96%b9%e6%b3%95%e3%80%82","status":"publish","type":"post","link":"https:\/\/www.silicloud.com\/zh\/blog\/%e8%b0%83%e6%9f%a5%e5%9f%ba%e4%ba%8eelasticsearch%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e8%ad%a6%e6%8a%a5%e9%80%9a%e7%9f%a5%e7%9a%84%e6%96%b9%e6%b3%95%e3%80%82\/","title":{"rendered":"\u8c03\u67e5\u57fa\u4e8eElasticsearch\u6570\u636e\u8fdb\u884c\u8b66\u62a5\u901a\u77e5\u7684\u65b9\u6cd5"},"content":{"rendered":"<h2>X-Pack\u7684\u89c2\u5bdf\u8005\u8b66\u62a5<\/h2>\n<p>\u5f00\u53d1\u8005\uff1aElastic<br \/>\n\u6536\u8d39\u7684<\/p>\n<p>\u8ba9\u6211\u4eec\u5f00\u59cb\u4f7f\u7528 Watcher<\/p>\n<p>\u5c1d\u8bd5\u4f7f\u7528Elasticsearch\u8b66\u62a5\u68c0\u6d4b\u63d2\u4ef6\u201cWatcher\u201d<br \/>\n\u9047\u5230\u548c\u5e94\u5bf9Elastic Stack\u8b66\u62a5\u7684\u95ee\u9898\u4e0e\u89e3\u51b3\u65b9\u6cd5<br \/>\n\u53ef\u89c6\u5316Elastic Stack\u9884\u8b66\u68c0\u6d4b\u7ed3\u679c-\u5f02\u5e38\u68c0\u6d4b\u901a\u77e5<br \/>\n\u4f7f\u7528Elasticsearch\u63d2\u4ef6\u201cShield\u201d\u548c\u201cWatcher\u201d\u8fdb\u884c\u975e\u6cd5\u8bbf\u95ee\u5ba1\u8ba1<br \/>\n\u5c1d\u8bd5\u4f7f\u7528Elastic Stack\u7684X-Pack\uff08Watcher\u90e8\u5206\uff09<\/p>\n<h2>Kibana\u4e2d\u7684X-Pack\u8b66\u62a5\u548c\u64cd\u4f5c\u8bbe\u7f6e<\/h2>\n<p>\u5f00\u53d1\u8005\uff1a\u5f39\u6027\u641c\u7d22<\/p>\n<p>&nbsp;<\/p>\n<h2>Kibana \u8b66\u62a5<\/h2>\n<p>\u4f7f\u7528Elastic Stack\u3001Prometheus\u548cFluentd\u76f8\u7ed3\u5408\u6765\u76d1\u89c6Kubernetes\u3002<br \/>\n\u53c2\u8003\u6587\u7ae0\u94fe\u63a5\uff1ahttps:\/\/www.elastic.co\/jp\/blog\/monitoring-kubernetes-with-the-elastic-stack-using-prometheus-and-fluentd<\/p>\n<blockquote><p>\u5728 Prometheus \u7684\u90e8\u7f72\u4e2d\uff0cAlertmanager \u88ab\u7981\u7528\u4e86\u3002\u5982\u679c\u4f7f\u7528 Elastic Stack \u6536\u96c6\u65e5\u5fd7\u548c\u6307\u6807\uff0c\u53ef\u4ee5\u4f7f\u7528 Kibana Alert \u6765\u5b9e\u73b0\u8b66\u62a5\u529f\u80fd\uff0c\u800c\u4e0d\u662f\u4f7f\u7528 Alertmanager\u3002\u4e0d\u4ec5\u53ef\u4ee5\u5229\u7528 Prometheus \u7684\u6307\u6807\uff0c\u8fd8\u53ef\u4ee5\u5229\u7528 Elasticsearch \u4e2d\u5b58\u50a8\u7684\u65e5\u5fd7\u548c\u5176\u4ed6\u7d22\u5f15\u7684\u6570\u636e\uff0c\u8fd8\u53ef\u4ee5\u5b9e\u73b0\u66f4\u9ad8\u7ea7\u7684\u57fa\u4e8e\u673a\u5668\u5b66\u4e60\u7684\u8b66\u62a5\u529f\u80fd\u3002<\/p><\/blockquote>\n<h2>\u5f39\u6027\u8b66\u62a5<\/h2>\n<p>\u5f00\u53d1\u8005\uff1aYelp<br \/>\n\u4f7f\u7528Python\u8fdb\u884c\u5f00\u53d1\u3002<br \/>\n\u4f7f\u7528Python\u5e93&#8221;elasticsearch-py&#8221;\u3002<br \/>\nhttps:\/\/pypi.org\/project\/elasticsearch\/<br \/>\n\u91c7\u7528Apache License 2.0\u8bb8\u53ef\u8bc1<br \/>\n\u7248\u672c\u4e3a0.2.4 (2020\/04\/17)<br \/>\nhttps:\/\/pypi.org\/project\/elastalert\/<\/p>\n<p>\u30fb\u4ec5\u4ec5\u57fa\u4e8e\u547d\u4ee4\u548c\u8bbe\u7f6e\u6587\u4ef6\uff08YAML\uff09\u8fdb\u884c\u64cd\u4f5c\u3002<br \/>\n\u30fb\u4ece0.2.0b2\u5f00\u59cb\u652f\u6301Elasticsearch 7.x\u3002<br \/>\n\u30fb\u4ece0.2.0\u5f00\u59cb\u652f\u6301Python3\u3002<br \/>\n\u30fb\u4e0d\u518d\u4fee\u590d\u9519\u8bef\u6216\u6dfb\u52a0\u529f\u80fd\u3002<br \/>\n\u30fb\u4e0d\u652f\u6301Python 3.9\u53ca\u4ee5\u4e0a\u7248\u672c\u3002<br \/>\n\u30fb\u4e0d\u652f\u6301Elasticsearch 8\u3002<br \/>\n\u8bf7\u4e0d\u8981\u8ba9\u5b83\u6d88\u4ea1\u3002ElastAlert\u7684\u7528\u4f8b\u975e\u5e38\u5f3a\u5927\u3002\uff032947<br \/>\n\u662f\u5426\u6709\u5176\u4ed6\u4eba\u6765\u7ef4\u62a4\u8fd9\u4e2a\u9879\u76ee\uff1f\uff032946<br \/>\nElastAlert\u9879\u76ee\u7684\u73b0\u72b6\uff032911<\/p>\n<p>AWS\u7684OpenSearch<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u5bfe\u5fdc\u3057\u3066\u3044\u306a\u3044\u3002\u6b63\u5e38\u306b\u52d5\u304b\u306a\u3044(\u5185\u90e8\u306eElasticsearch \u30d0\u30fc\u30b8\u30e7\u30f3\u306f7.10.2\u3060\u304c\u3001\u30d0\u30fc\u30b8\u30e7\u30f3\u30921.0.0\u3068\u8fd4\u3057\u3066\u3057\u307e\u3046\u3002\u30d0\u30fc\u30b8\u30e7\u30f3\u30c1\u30a7\u30c3\u30af\u3067Elasticsearch 5\u306e\u51e6\u7406\u306b\u3044\u3063\u3066\u3057\u307e\u3046)<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">ElastAlert2\u306f\u5bfe\u5fdc\u3092\u958b\u59cb\u3057\u305f\u3002<\/ul>\n<p>Elasticsearch\u7684Bearer\u8ba4\u8bc1<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u5bfe\u5fdc\u3057\u3066\u3044\u306a\u3044\u3002<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">ElastAlert2\u306f\u5bfe\u5fdc\u3057\u3066\u308b\u3002<\/ul>\n<p>Elasticsearch\u7684ApiKey\u8ba4\u8bc1\u65b9\u5f0f.<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u5bfe\u5fdc\u3057\u3066\u3044\u306a\u3044\u3002<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">ElastAlert2\u306f\u5bfe\u5fdc\u3057\u3066\u308b\u3002<\/ul>\n<p>Elasticsearch\u7684\u4ee3\u7406\u8fde\u63a5<\/p>\n<p>\u7f3a\u5c11\u4ee3\u7406\u914d\u7f6e\u529f\u80fd<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u5bfe\u5fdc\u3057\u3066\u3044\u306a\u3044\u3002<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">ElastAlert2\u3082\u5bfe\u5fdc\u3057\u3066\u3044\u306a\u3044\u3002<\/ul>\n<p>Python 3.9\u53ca\u5176\u4ee5\u540e\u7684\u7248\u672c\u65e0\u6cd5\u6b63\u5e38\u8fd0\u884c\u3002<\/p>\n<p>\u5728Python 3.9\u4e2d\uff0cblist\u4e0d\u518d\u8d77\u4f5c\u7528\u3002<br \/>\nElastalert\u5728Python 3.9\u4e0a\u7531\u4e8eblist\u4f9d\u8d56\u9879\u51fa\u73b0\u6545\u969c\u3002<\/p>\n<ul class=\"post-ul\">ElastAlert2\u306f\u5bfe\u5fdc\u3057\u3066\u308b\u3002<\/ul>\n<p>\u53ea\u6709\u6309\u7167\u4ee5\u4e0b\u65b9\u5f0f\u7f16\u5199\uff0cAWS SNS\u624d\u80fd\u6b63\u5e38\u8fd0\u884c\u3002<\/p>\n<pre class=\"post-pre\"><code>    <span class=\"na\">alert<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"na\">sns<\/span><span class=\"pi\">:<\/span>\r\n          <span class=\"na\">aws_region<\/span><span class=\"pi\">:<\/span> <span class=\"s1\">'<\/span><span class=\"s\">us-east-1'<\/span>\r\n    <span class=\"na\">sns_topic_arn<\/span><span class=\"pi\">:<\/span> <span class=\"s1\">'<\/span><span class=\"s\">arn:aws:sns:us-east-1:123456789:somesnstopic'<\/span>\r\n    <span class=\"na\">aws_access_key_id<\/span><span class=\"pi\">:<\/span> <span class=\"s1\">'<\/span><span class=\"s\">XXXXXXXXXXXXXXXXXX'<\/span>\r\n    <span class=\"na\">aws_secret_access_key<\/span><span class=\"pi\">:<\/span> <span class=\"s1\">'<\/span><span class=\"s\">YYYYYYYYYYYYYYYYYYYY'<\/span>\r\n<\/code><\/pre>\n<p>\u5f53\u641c\u7d22\u7ed3\u679c\u8d85\u8fc710,000\u6761\u65f6\uff0c\u5728\u641c\u7d22\u7ed3\u679c\u9875\u9762\u5c06\u663e\u793a10,000\u6761\u4ee5\u4e0a\u3002<\/p>\n<p>\u5982\u679c\u5c06track_total_hits\u8bbe\u7f6e\u4e3atrue\uff0c\u5c31\u53ef\u4ee5\u641c\u7d22\u8d85\u8fc710,000\u6b21\u547d\u4e2d\u7684\u7ed3\u679c\uff0c\u4f46\u662f\u5f53\u524d\u7684\u5b9e\u73b0\u4e0d\u652f\u6301\u5c06track_total_hit\u8bbe\u7f6e\u4e3atrue\u7684\u914d\u7f6e\u66f4\u6539\u3002<\/p>\n<p>\u5f53\u5c06Elasticsearch\u5347\u7ea7\u81f37.X\u7248\u672c\u540e\uff0c\u547d\u4e2d\u6570(hits)\u53d8\u4e3a10,000\u3002<\/p>\n<p>\u5728\u9ed1\u540d\u5355\u3001\u767d\u540d\u5355\u4e2d\uff0c\u6709\u4e00\u4e2a1024\u7684\u9650\u5236\u3002<\/p>\n<p>\u9ed1\u540d\u5355\u8fc7\u6ee4\u5668\u5305\u542b10,000\u591a\u4e2a\u6761\u76ee\uff0c\u901f\u5ea6\u6781\u6162<br \/>\n\u5f53\u6587\u4ef6\u4e2d\u7684\u9ed1\u540d\u5355\u89c4\u5219\u8d85\u8fc71024\u4e2a\u6761\u76ee\u65f6\uff0c\u201c\u89e3\u6790\u67e5\u8be2\u5931\u8d25\u201d<br \/>\n\u9ed1\u540d\u5355\u884c\u6570\u9650\u5236<\/p>\n<p>\u7535\u5b50\u90ae\u4ef6\u63d0\u9192\u7684\u9650\u5236<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Microsoft 365(\u65e7\u540d\u79f0Office 365)\u306ffrom_addr\u306b\u8a2d\u5b9a\u306b\u5bfe\u5fdc\u3057\u3066\u3044\u307e\u305b\u3093\u3002to,cc,bcc\u306b\u6307\u5b9a\u306f\u554f\u984c\u7121\u3057\u3002<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">Gmail\u3092from_addr\u306b\u8a2d\u5b9a\u3059\u308b\u5834\u5408\u3001Google\u306e\u8a2d\u5b9a\u3067\u5b89\u5168\u6027\u306e\u4f4e\u3044\u30a2\u30d7\u30ea\u306e\u30a2\u30af\u30bb\u30b9\u3092\u6709\u52b9\u306b\u3057\u306a\u3044\u3068\u30e1\u30fc\u30eb\u306e\u9001\u4fe1\u304c\u3067\u304d\u307e\u305b\u3093\u3002<\/ul>\n<p>Kibana\u7684\u4eea\u8868\u76d8\u76f8\u5173\u529f\u80fd\u65e0\u6cd5\u6b63\u5e38\u8fd0\u884c\u3002<\/p>\n<p>\u76ee\u524d\u7684Elasticsearch\u7248\u672c\u547d\u540d\u4e3a.kibana*\uff0c\u4f46\u6211\u4eec\u7684\u5185\u90e8\u903b\u8f91\u4e2d\u5f15\u7528\u4e86kibana-int\u8fd9\u4e2a\u7d22\u5f15\u3002\u56e0\u6b64\uff0c\u6211\u4eec\u5fc5\u987b\u4fee\u6539\u7a0b\u5e8f\u624d\u80fd\u6b63\u5e38\u8fd0\u884c\u3002\u53e6\u5916\uff0c\u5173\u4e8eDashboard\u7684\u903b\u8f91\u4e5f\u4e0d\u517c\u5bb9Elasticsearch 7\u3002<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">elastalert-rule-from-kibana<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">use_kibana_dashboard<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">use_kibana4_dashboard<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">kibana4_start_timedelta<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">kibana4_end_timedelta<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">download_dashboard<\/ul>\n<p>\u4e0b\u8f7d\u4eea\u8868\u677f\u6587\u4ef6\u5b58\u5728\u95ee\u9898\u3002<br \/>\n\u4eea\u8868\u677f\u6587\u4ef6\u7684\u4e0b\u8f7d\u94fe\u63a5\u5982\u4e0b\uff1a<br \/>\nhttps:\/\/elastalert.readthedocs.io\/en\/latest\/recipes\/writing_filters.html#loading-filters-directly-from-kibana-3<br \/>\nhttps:\/\/github.com\/Yelp\/elastalert\/issues\/1481<\/p>\n<p>\u5f53\u524d\u7684\u5199\u4f5c<\/p>\n<pre class=\"post-pre\"><code>filter:\r\n  download_dashboard: \"My Dashboard Name\"\r\n<\/code><\/pre>\n<p>\u51c6\u786e\u7684\u8bb0\u5f55<\/p>\n<pre class=\"post-pre\"><code>filter:\r\n  - term:\r\n      download_dashboard: \"My Dashboard Name\"\r\n<\/code><\/pre>\n<h4>ElastAlert\u7684\u8b66\u62a5\u901a\u77e5\u63a5\u6536\u8005<\/h4>\n<p>&nbsp;<\/p>\n<div>\n<div class=\"post-table\">\u30a2\u30e9\u30fc\u30c8\u901a\u77e5\u5148\u5099\u8003Command\u30a2\u30e9\u30fc\u30c8\u901a\u77e5\u78ba\u8a8d\u6e08Email\u30a2\u30e9\u30fc\u30c8\u901a\u77e5\u78ba\u8a8d\u6e08<br \/>\ngmail\u307e\u305f\u306foffice365\u3067\u3046\u307e\u304f\u3044\u304b\u306a\u3044\u3068\u3044\u3046issue\u3092\u898b\u304b\u3051\u308b\u554f\u984c\u3042\u308a\u305d\u3046\u3002gmail\u307e\u305f\u306foffice365\u306ffrom_addr\u306b\u6307\u5b9a\u3057\u306a\u3051\u308c\u3070\u5927\u4e08\u592bJira\u4ee5\u4e0b\u306e\u3082\u306e\u304c\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u306b\u8a18\u8f09\u3057\u5fd8\u308c\u3066\u3044\u308b<br \/>\n\u30fbjira_assignee<br \/>\n\u30ab\u30b9\u30bf\u30e0\u30d5\u30a3\u30fc\u30eb\u30c9\u3067\u6b63\u5e38\u306b\u52d5\u304b\u306a\u3044\u60c5\u5831\u3042\u308a<br \/>\n<a href=\"https:\/\/github.com\/Yelp\/elastalert\/issues\/3073\" target=\"_blank\" rel=\"nofollow noopener\">Jira customfield not taking argument #3073<\/a><br \/>\n<a href=\"https:\/\/github.com\/Yelp\/elastalert\/issues\/3108\" target=\"_blank\" rel=\"nofollow noopener\">Trying to assign Epic Link to Jira ticket #3108<\/a>OpsGenie\u4ee5\u4e0b\u306e\u3082\u306e\u304c\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u306b\u8a18\u8f09\u3057\u5fd8\u308c\u3066\u3044\u308b<br \/>\n\u30fbopsgenie_addr<br \/>\n\u30fbopsgenie_proxy<br \/>\n\u30fbopsgenie_detailsAWS SNS\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u306e\u8a18\u8f09\u304c\u53e4\u3044<br \/>\n\u30fbaws_access_key\u2192aws_access_key_id<br \/>\n\u30fbaws_secret_key\u2192aws_secret_access_key<br \/>\n\u30fbprofile\u2192aws_profileHipChatHipChat\u306f2019\/02\u306b\u30b5\u30fc\u30d3\u30b9\u7d42\u4e86\u3057\u3066\u3044\u308bStrideStride\u306f2019\/02\u306b\u30b5\u30fc\u30d3\u30b9\u7d42\u4e86\u3057\u3066\u3044\u308bMicrosoft Teams\u30a2\u30e9\u30fc\u30c8\u901a\u77e5\u78ba\u8a8d\u6e08Slack\u30a2\u30e9\u30fc\u30c8\u901a\u77e5\u78ba\u8a8d\u6e08<br \/>\n\u4ee5\u4e0b\u306e\u3082\u306e\u304c\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u306b\u8a18\u8f09\u3057\u5fd8\u308c\u3066\u3044\u308b<br \/>\n\u30fbslack_ca_certs<br \/>\n\u30fbslack_ignore_ssl_errors<br \/>\n\u30fbslack_timeoutMattermost\u30a2\u30e9\u30fc\u30c8\u901a\u77e5\u78ba\u8a8d\u6e08Telegram\u30a2\u30e9\u30fc\u30c8\u901a\u77e5\u78ba\u8a8d\u6e08<br \/>\n\u4ee5\u4e0b\u306e\u3082\u306e\u304c\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u306b\u8a18\u8f09\u3057\u5fd8\u308c\u3066\u3044\u308b<br \/>\n\u30fbtelegram_proxy_login<br \/>\n\u30fbtelegram_proxy_passGoogleChat<br \/>\nPagerDuty<br \/>\nPagerTree\u6700\u65b0\u306e0.2.4\u3067\u6b63\u5e38\u306b\u52d5\u4f5c\u3057\u306a\u3044<br \/>\n\u4ee5\u4e0b\u306e\u3082\u306e\u304c\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u306b\u8a18\u8f09\u3057\u5fd8\u308c\u3066\u3044\u308b<br \/>\n\u30fbpagertree_proxyExotelExotel\u306f\u65e5\u672c\u3067\u30b5\u30dd\u30fc\u30c8\u5916\u306e\u305f\u3081\u672a\u78ba\u8a8dTwilio\u30a2\u30e9\u30fc\u30c8\u901a\u77e5\u78ba\u8a8d\u6e08VictorOps\u30a2\u30e9\u30fc\u30c8\u901a\u77e5\u78ba\u8a8d\u6e08Gitter\u30a2\u30e9\u30fc\u30c8\u901a\u77e5\u78ba\u8a8d\u6e08ServiceNow\u30a2\u30e9\u30fc\u30c8\u901a\u77e5\u78ba\u8a8d\u6e08Debug<br \/>\nStomp\u6700\u65b0\u306e0.2.4\u3067\u6b63\u5e38\u306b\u52d5\u4f5c\u3057\u306a\u3044<br \/>\n\u4ee5\u4e0b\u306e\u3082\u306e\u304c\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u306b\u8a18\u8f09\u3057\u5fd8\u308c\u3066\u3044\u308b<br \/>\n\u30fbstomp_sslAlerta\u30a2\u30e9\u30fc\u30c8\u901a\u77e5\u306f\u52d5\u3044\u3066\u3044\u308b\u3068\u3044\u3046\u60c5\u5831\u3042\u308a<br \/>\n\u4ee5\u4e0b\u306e\u3082\u306e\u304c\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u306b\u8a18\u8f09\u3057\u5fd8\u308c\u3066\u3044\u308b<br \/>\n\u30fbalerta_api_skip_sslHTTP POST<br \/>\nLine Notify\u6700\u65b0\u306e0.2.4\u3067\u6b63\u5e38\u306b\u52d5\u4f5c\u3057\u306a\u3044TheHive\u30a2\u30e9\u30fc\u30c8\u901a\u77e5\u306f\u52d5\u3044\u3066\u3044\u308b\u3068\u3044\u3046\u60c5\u5831\u3042\u308a<br \/>\n\u4ee5\u4e0b\u306e\u3082\u306e\u304c\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u306b\u8a18\u8f09\u3057\u5fd8\u308c\u3066\u3044\u308b<br \/>\n\u30fbhive_verifyZabbix\u30fb<a href=\"https:\/\/elastalert.readthedocs.io\/en\/latest\/ruletypes.html#zabbix\" target=\"_blank\" rel=\"nofollow noopener\">\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8<\/a>\u3067\u300czbx_item\u300d\u3068\u3044\u3046\u8a18\u8f09\u3055\u308c\u3066\u3044\u308b\u306e\u306f\u300czbx_key\u300d\u3002zbx_item\u3068\u66f8\u304f\u3068\u300cMissing required option(s): zbx_key\u300d\u306e\u30a8\u30e9\u30fc\u304c\u51fa\u308b\u3002<br \/>\n\u30fb\u8a2d\u5b9a\u3092\u8ffd\u52a0\u3057\u3066\u52d5\u304b\u3059\u3068\u30a8\u30e9\u30fc\u304c\u51fa\u308b\u3002\u30d0\u30b0\u304c\u3042\u308b\u3088\u3046\u3067\u3059\u3002<br \/>\n(expected 2, got 1)Could not import module zabbix: not enough values to unpack<br \/>\n<a href=\"https:\/\/github.com\/Yelp\/elastalert\/issues\/2601\" target=\"_blank\" rel=\"nofollow noopener\">Zabbix alert #2601<\/a><br \/>\n<a href=\"https:\/\/github.com\/Yelp\/elastalert\/issues\/2621\" target=\"_blank\" rel=\"nofollow noopener\">Zabbix alert module error #2621<\/a><br \/>\n<a href=\"https:\/\/github.com\/Yelp\/elastalert\/issues\/2586\" target=\"_blank\" rel=\"nofollow noopener\">Elastalet fails if alerter type zabbix is used: &#8220;ValueError: not enough values to unpack&#8221; [bug] #2586<\/a><br \/>\n\u4ee5\u4e0b\u306e\u5bfe\u5fdc\u3067\u6b63\u5e38\u306b\u52d5\u4f5c\u3057\u307e\u3059\u3002\u52d5\u4f5c\u78ba\u8a8d\u624b\u4f1d\u3044\u307e\u3057\u305f<br \/>\n<a href=\"https:\/\/github.com\/Yelp\/elastalert\/pull\/2640\" target=\"_blank\" rel=\"nofollow noopener\">Bugfix and better error handling on zabbix alerter #2640<\/a><\/div>\n<\/div>\n<h4>\u5f39\u6027\u8b66\u62a5\u670d\u52a1\u5668Docker\u955c\u50cf<\/h4>\n<p>\u6211\u5bf9ElastAlert Server\u7684\u672a\u6765\u7ef4\u62a4\u611f\u5230\u4e0d\u5b89\u3002bitsensor\/elastalert\u5904\u4e8e\u4e0d\u7ef4\u62a4\u7684\u72b6\u6001\u3002\u8003\u8651\u5230\u672a\u6765\u53ef\u80fd\u9700\u8981\u901a\u8fc7johnsusek\/elastalert-server\u7684fork\u8fdb\u884c\u81ea\u5df1\u7684\u7ef4\u62a4\uff0c\u6211\u8ba4\u4e3a\u503c\u5f97\u8003\u8651\u91c7\u7528\u4ee5\u4e0b\u89e3\u51b3\u65b9\u6848\uff1a<br \/>\n&#8211; \u5bf9\u65b0\u7684Node.js\u8fdb\u884c\u9002\u914d\u3002<br \/>\n&#8211; \u5bf9Elasticsearch\u8fdb\u884c\u4e3b\u8981\u7248\u672c\u5347\u7ea7\u7684\u9002\u914d\uff08\u6700\u8fd1\u7684\u7248\u672c\u4e3a8.x\uff09\u3002<br \/>\n&#8211; \u5982\u679c\u8981\u4f7f\u7528ElastAlert2\uff0c\u9664\u4e86praecoapp\/elastalert-server\u548ckarql\/elastalert2-server\u8fd9\u4e24\u4e2a\u9009\u9879\u5916\uff0c\u6ca1\u6709\u5176\u4ed6\u9009\u62e9\u3002<\/p>\n<div>\n<div class=\"post-table\">Docker\u30a4\u30e1\u30fc\u30b8\u540d\u30bf\u30b0ElastAlert\u5099\u8003<a href=\"https:\/\/hub.docker.com\/r\/bitsensor\/elastalert\/\" target=\"_blank\" rel=\"nofollow noopener\">bitsensor\/elastalert<\/a>2.0.10.1.39Elastcserach 7.x\u3067\u554f\u984c\u304c\u767a\u751f<a href=\"https:\/\/hub.docker.com\/r\/bitsensor\/elastalert\/\" target=\"_blank\" rel=\"nofollow noopener\">bitsensor\/elastalert<\/a>lastet0.1.39Elastcserach 7.x\u3067\u554f\u984c\u304c\u767a\u751f<a href=\"https:\/\/hub.docker.com\/r\/bitsensor\/elastalert\/\" target=\"_blank\" rel=\"nofollow noopener\">bitsensor\/elastalert<\/a>3.0.0-beta.00.2.0b2<br \/>\n<a href=\"https:\/\/hub.docker.com\/r\/bitsensor\/elastalert\/\" target=\"_blank\" rel=\"nofollow noopener\">bitsensor\/elastalert<\/a>3.0.0-beta.1\u672a\u78ba\u8a8d<br \/>\n<a href=\"https:\/\/hub.docker.com\/r\/servercentral\/elastalert\" target=\"_blank\" rel=\"nofollow noopener\">servercentral\/elastalert<\/a>latest0.2.1bitsensor\/elastalert\u30d5\u30a9\u30fc\u30af<a href=\"https:\/\/hub.docker.com\/r\/daichi703n\/elastalert\" target=\"_blank\" rel=\"nofollow noopener\">daichi703n\/elastalert<\/a>0.2.1-dev20.2.1+bugfixservercentral\/elastalert\u30d5\u30a9\u30fc\u30af<br \/>\njfcantu\/elastalert:v0.1.1\u306e\u30a4\u30e1\u30fc\u30b8\u4f7f\u7528\uff1f\u3002\u305d\u306e\u4ed6\u306e\u30d0\u30b0\u4fee\u6b63\u306f\u4ee5\u4e0b\u306e\u30b5\u30a4\u30c8\u3092\u53c2\u7167\u3002<br \/>\n<a href=\"https:\/\/designetwork.daichi703n.com\/entry\/2020\/02\/10\/praeco-elastalert-issue-with-es7\" target=\"_blank\" rel=\"nofollow noopener\">Praeco + ElastAlert2.0 + ES7.x \u69cb\u6210\u306e\u4e0d\u5177\u5408\u5bfe\u5fdc\u65b9\u6cd5<\/a><br \/>\n<a href=\"https:\/\/github.com\/daichi703n\/elastalert-server\" target=\"_blank\" rel=\"nofollow noopener\">daichi703n\/elastalert-server (GitHub)<\/a><a href=\"https:\/\/hub.docker.com\/r\/karql\/elastalert2-server\" target=\"_blank\" rel=\"nofollow noopener\">karql\/elastalert2-server<\/a>latestElastAlert2 2.9.0bitsensor\/elastalert\u30d5\u30a9\u30fc\u30af<br \/>\nnode.js\u304b\u3089TypeScript\u306b\u5909\u66f4\u3057\u3066\u3044\u308b<a href=\"https:\/\/hub.docker.com\/r\/praecoapp\/elastalert-server\" target=\"_blank\" rel=\"nofollow noopener\">praecoapp\/elastalert-server<\/a>latestElastAlert2 2.9.0servercentral\/elastalert\u30d5\u30a9\u30fc\u30af<br \/>\nPraeco\u7528ElastAlert Server\u306e\u6700\u65b0\u7248<br \/>\nElasticsearch 8\u5bfe\u5fdc<\/div>\n<\/div>\n<h4>\u7531\u4e8e\u7d22\u5f15\u6253\u5f00\u8fc7\u591a\uff0c\u5bfc\u81f4Java\u5806\u5185\u5b58\u67af\u7aed\u3002<\/h4>\n<p>\u6709\u65f6\u4f1a\u53d1\u751fcircuit_breaking_exception\u6545\u969c<br \/>\n\u2192 \u8c03\u6574ElasticSearch\u7684\u5806\u5927\u5c0f<br \/>\n\u2192 \u4fee\u6539ElasticSearch\u7684indices.breaker.total.limit<br \/>\n\u2192 \u5220\u9664ElasticSearch\u7684\u7d22\u5f15\u6570\u636e\uff0c\u6216\u5173\u95ed\u4e0d\u9700\u8981\u7684\u7d22\u5f15\u6570\u636e<br \/>\n\u7531\u4e8eElasticsearch\u6253\u5f00\u8fc7\u591a\u7684\u7d22\u5f15\uff0c\u5bfc\u81f4\u5806\u5185\u5b58\u8017\u5c3d<br \/>\nelastalert\u611f\u5230\u975e\u5e38\u4e0d\u9ad8\u5174\uff08circuit_breaking_exception\uff0c\u6570\u636e\u592a\u5927\uff09#2485<br \/>\ncircuit_breaking_exception\uff0c\u6570\u636e\u592a\u5927#349<br \/>\n\u5347\u7ea7\u81f36.2.4\u540e\uff0c\u56de\u8def\u4e2d\u65ad\u6570\u636e\u592a\u5927\u5f02\u5e38#31197<br \/>\nElastalert\u90e8\u7f72\u5931\u8d25<\/p>\n<h4>\u8bf7\u53c2\u8003\u7f51\u5740\u3002<\/h4>\n<p>\u4f7f\u7528Elastic Stack\u76d1\u63a7Kubernetes\u7cfb\u7edf<br \/>\n\u4f7f\u7528ElastAlert\u76d1\u63a7\u548c\u901a\u77e5Elasticsearch\u7d22\u5f15<br \/>\n\u5e0c\u671b\u4f7f\u7528elastalert\u81ea\u52a8\u68c0\u6d4b\u5e76\u901a\u77e5\u5e94\u7528\u7a0b\u5e8f\u5f02\u5e38<br \/>\n\u901a\u8fc7elastalert\u548cElasticSearch\u7b80\u4fbf\u7075\u6d3b\u5730\u8bbe\u7f6e\u8b66\u62a5<br \/>\n\u4f7f\u7528ElastAlert\u521b\u5efa\u81ea\u5b9a\u4e49\u89c4\u5219<br \/>\n\u5e0c\u671b\u5728\u53d1\u73b0\u9519\u8bef\u65e5\u5fd7\u65f6\u901a\u8fc7ElasticSearch\u548cElastalert\u8fdb\u884c\u901a\u77e5<br \/>\n\u901a\u8fc7\u6269\u5c55ElastAlert\u7684\u76d1\u63a7\u89c4\u5219\u6765\u83b7\u5f97\u4e00\u70b9\u70b9\u5e78\u798f<br \/>\n\u4f7f\u7528Elasticsearch\u8fdb\u884c\u670d\u52a1\u76d1\u63a7\uff0c\u7a0d\u7a0d\u611f\u5230\u5e78\u798f<br \/>\n\u901a\u8fc7ElastAlert\u76d1\u63a7AWS ElasticSearch Service\u7684\u65e5\u5fd7<br \/>\n\u5e0c\u671b\u901a\u8fc7twitter -&gt; fluentd -&gt; elasticsearch -&gt; elastalert -&gt; slack\u5b9e\u73b0\u81ea\u6211\u76d1\u89c6\u7684\u4eba\u751f\u3002<br \/>\n\u4f7f\u7528elastalert\u5411slack\u53d1\u9001\u8b66\u62a5<br \/>\n\u901a\u8fc7EFK Stack\u5bf9Kubernetes\u4e8b\u4ef6\u8fdb\u884c\u8b66\u62a5<br \/>\n\u4f7f\u7528ElastAlert\u8fdb\u884c\u5927\u89c4\u6a21\u7684Elasticsearch\u8b66\u62a5\uff0c\u7b2c\u4e00\u90e8\u5206<br \/>\n\u4f7f\u7528Elastalert\u76d1\u63a7\u78c1\u76d8\u589e\u957f\u60c5\u51b5<\/p>\n<h4>\u6837\u54c1<\/h4>\n<p>elastalert\/example_rules<br \/>\nandromedarabbit\/elastalert-rule.yaml<br \/>\n\u4f7f\u7528elastalert\u53d1\u9001\u5230slack\u7684\u8b66\u62a5<\/p>\n<p>CPU\u4f7f\u7528\u7387\u7684Elastalert\u89c4\u5219<br \/>\n\u6267\u884cElastalert\u89c4\u5219\u65f6\u51fa\u9519\uff1aIOError: [Errno 2]\u6ca1\u6709\u627e\u5230&#8217;config.yaml&#8217;\u6587\u4ef6\u6216\u76ee\u5f55<br \/>\nELK\uff1a\u57fa\u4e8eElasticSearch\u6570\u636e\u7684ElastAlert\u62a5\u8b66<br \/>\nmanankalra\/elastalert-tutorial<br \/>\n&#8211; elastalert_cpu_watch.yaml<br \/>\n&#8211; elastalert_filesystem_watch.yaml<br \/>\n&#8211; elastalert_memory_watch.yaml<\/p>\n<h2>\u5f39\u6027\u8b66\u62a5\u7684\u5206\u652f\u7248\u672c<\/h2>\n<p>\u5927\u6570\u636e\u7cbe\u54c1\/\u5f39\u6027\u8b66\u62a5<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">ElastAlert 0.2.4\u30d9\u30fc\u30b9<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">crontrigger, must_not\u306a\u3069\u3092\u8ffd\u52a0\u3057\u3066\u3044\u308b\u3002<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Python 3.9\u4ee5\u964d\u306f\u52d5\u304d\u307e\u305b\u3093\u3002<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">Elasticsearch 8\u306b\u5bfe\u5fdc\u3057\u3066\u3044\u307e\u305b\u3093\u3002<\/ul>\n<p>\u81ea\u52a81-OSS\/\u5f39\u6027\u9884\u8b66<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">ElastAlert 0.2.1\u30d9\u30fc\u30b9<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">auto resolve alert\u3001generate_kibana6_link\u306a\u3069\u3092\u8ffd\u52a0\u3057\u3066\u3044\u308b\u3002<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Python 3.9\u4ee5\u964d\u306f\u52d5\u304d\u307e\u305b\u3093\u3002<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">Elasticsearch 8\u306b\u5bfe\u5fdc\u3057\u3066\u3044\u307e\u305b\u3093\u3002<\/ul>\n<p>sherifabdlnaby\/elastalert\u7684\u7248\u672c\u662fv0.4.0\u3002<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">ElastAlert 0.2.1\u30d9\u30fc\u30b9<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Jinja2 Options\u306a\u3069\u3092\u8ffd\u52a0\u3057\u3066\u3044\u308b\u3002<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Python 3.9\u4ee5\u964d\u306f\u52d5\u304d\u307e\u305b\u3093\u3002<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">Elasticsearch 8\u306b\u5bfe\u5fdc\u3057\u3066\u3044\u307e\u305b\u3093\u3002<\/ul>\n<p>JasperJuergensen\u7684elastalert<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">ElastAlert 0.2.4\u30d9\u30fc\u30b9<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Python 3.9\u4ee5\u964d\u306f\u52d5\u304d\u307e\u305b\u3093\u3002<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">Elasticsearch 8\u306b\u5bfe\u5fdc\u3057\u3066\u3044\u307e\u305b\u3093\u3002<\/ul>\n<p>v0.3.0\uff082020\/6\/20\uff09<br \/>\n\u8bf7\u8bbf\u95ee\u4ee5\u4e0b\u94fe\u63a5\u4e86\u89e3\u66f4\u591a\u4fe1\u606f\uff1a<br \/>\nhttps:\/\/github.com\/JasperJuergensen\/elastalert\/blob\/master\/changelog.md<\/p>\n<blockquote><p>\u91cd\u7ec4<br \/>\n\u5c06\u89c4\u5219\u7c7b\u578b\u653e\u5728\u5b83\u4eec\u81ea\u5df1\u7684\u6a21\u5757\u4e2d\uff0c\u800c\u4e0d\u662f\u4e00\u4e2a\u6587\u4ef6\u4e2d<br \/>\n\u5c06\u8b66\u62a5\u5668\u653e\u5728\u5b83\u4eec\u81ea\u5df1\u7684\u6a21\u5757\u4e2d\uff0c\u800c\u4e0d\u662f\u4e00\u4e2a\u6587\u4ef6\u4e2d<br \/>\n\u5c06\u589e\u5f3a\u529f\u80fd\u653e\u5728\u5b83\u4eec\u81ea\u5df1\u7684\u6a21\u5757\u4e2d\uff0c\u800c\u4e0d\u662f\u4e00\u4e2a\u6587\u4ef6\u4e2d<br \/>\n\u5c06\u52a0\u8f7d\u5668\u653e\u5728\u5b83\u4eec\u81ea\u5df1\u7684\u6a21\u5757\u4e2d\uff0c\u800c\u4e0d\u662f\u4e00\u4e2a\u6587\u4ef6\u4e2d<br \/>\n\u4f7f\u7528\u65b0\u7684\u5168\u5c40\u914d\u7f6e\u5bf9\u8c61\uff0c\u800c\u4e0d\u662f\u4e00\u4e2a\u5b57\u5178<br \/>\n\u6dfb\u52a0<br \/>\nMAAS\u89c4\u5219<br \/>\n\u7528\u4e8e\u7a81\u53d1\u548c\u7a81\u53d1\u5ea6\u91cf\u805a\u5408\u89c4\u5219\u7684\u65b0\u6307\u6807<br \/>\n\u76f8\u5173\u6027\u89c4\u5219<br \/>\n\u67e5\u8be2<br \/>\n\u89c4\u5219\u7c7b\uff0c\u8986\u76d6\u4e86\u4e4b\u524d\u7531elastalerter\u5bf9\u8c61\u63d0\u4f9b\u7684\u4e00\u4e9b\u529f\u80fd<br \/>\n\u7528\u4e8e\u6267\u884c\u89c4\u5219\u8fc7\u7a0b\u4e2d\u7684\u5f02\u5e38\u7684EARuntimeException<br \/>\n\u7528\u4e8e\u914d\u7f6e\u89c4\u5219\u9636\u6bb5\u5f15\u53d1\u7684\u5f02\u5e38\u7684EAConfigExceptions<br \/>\n\u4fee\u590d<br \/>\n\u4fee\u590d\u4e86\u7a81\u53d1\u5ea6\u91cf\u805a\u5408\u89c4\u5219\u7684\u7a97\u53e3\u95ee\u9898<\/p><\/blockquote>\n<p>jsonar\/elastalert\u7684\u4e2d\u6587\u91ca\u4e49\u4e3a\uff1aJsonar\/elastalert<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">ElastAlert 0.1.35\u30d9\u30fc\u30b9<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Python 3.8\u3001elasticsearch-py\u30d0\u30fc\u30b8\u30e7\u30f3\u30a2\u30c3\u30d7\u306a\u3069<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Python 3.9\u4ee5\u964d\u306f\u52d5\u304d\u307e\u305b\u3093\u3002<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">Elasticsearch 8\u306b\u5bfe\u5fdc\u3057\u3066\u3044\u307e\u305b\u3093\u3002<\/ul>\n<h2>\u5f39\u6027\u8b66\u62a52<\/h2>\n<p>\u7ef4\u62a4\u8005\uff1aJason Ertel<br \/>\n\u8fd9\u4e2a\u7248\u672c\u7684Elastalert2\u6709\u4e00\u4e9bYelp\/elastalert\u4e2d\u6ca1\u6709\u7684\u529f\u80fd\u3002<br \/>\n\u8bb8\u53ef\u8bc1\u4e3aApache License 2.0\u3002<br \/>\n2.9.0\u7248\u672c\u4e8e2022\u5e7412\u670812\u65e5\u53d1\u5e03\u3002<br \/>\n\u8be6\u60c5\u8bf7\u53c2\u8003https:\/\/pypi.org\/project\/elastalert2\/\u3002<\/p>\n<p>\u30fb\u91cd\u6784\u4ee3\u7801\uff0c\u6dfb\u52a0\u6d4b\u8bd5\u4ee3\u7801\u3002<br \/>\n\u30fb\u652f\u6301Python 3.10\u3002<br \/>\n\u30fb\u9002\u914dElasticsearch 7\u30018\u548cOpensearch\u3002<br \/>\n\u30fb\u65b0\u589eDatadog\u3001Discord\u3001Chartwork\u3001Dingtalk\u3001Rocket.Chat\u3001Amazon SES\u3001Tencent SMS\u3001Alertmanager\u3001HTTP POST 2\u7b49\u4f5c\u4e3a\u62a5\u8b66\u901a\u77e5\u7684\u76ee\u6807\u3002<br \/>\n\u30fb\u4fee\u590d\u4e86\u8bb8\u591abug\uff08Line Notify\u3001Stomp\u3001Zabbix\u3001Pagertree\u6b63\u5e38\u8fd0\u884c\uff0c\u4fee\u590d\u4e86AWS SNS\u7684bug\u7b49\uff09\u3002<br \/>\n\u30fb\u8fd8\u63d0\u4f9b\u4e86Docker\u955c\u50cf\u548cHelm\u56fe\u8868\u3002<\/p>\n<p>&nbsp;<\/p>\n<h2>\u5f39\u6027\u8b66\u62a5 Kibana \u63d2\u4ef6<\/h2>\n<p>\u5f00\u53d1\u8005\uff1aBitSensor<br \/>\n\u8bb8\u53ef\u8bc1\u4e3a3\u6761\u6b3e\u7684BSD\u8bb8\u53ef\u8bc1\uff08\u6539\u7248\uff09<br \/>\n\u7248\u672c\u53f71.1.0\uff082019\/07\/22\uff09<\/p>\n<p>\u30fbElastAlert\u89c4\u5219\u6587\u4ef6\u7f16\u8f91\u5668<br \/>\n\u30fb\u53ef\u4ee5\u5c06ElastAlert\u5d4c\u5165\u5230Kibana\u9009\u9879\u5361\u4e2d\u3002<br \/>\n\u30fb\u53ea\u80fd\u7ba1\u7406\u8b66\u62a5\u89c4\u5219\u76ee\u5f55\u4e0b\u7684\u6587\u4ef6\u3002<br \/>\n\u30fb\u5f53\u5b58\u5728\u76f8\u540c\u540d\u79f0\u7684\u89c4\u5219\u6587\u4ef6\u65f6\uff0c\u65b0\u5efa\u76f8\u540c\u540d\u79f0\u7684\u89c4\u5219\u6587\u4ef6\u4f1a\u8fdb\u884c\u8986\u76d6\u3002<br \/>\n\u30fb\u8fd8\u4e0d\u80fd\u53c2\u8003\u89c4\u5219\u6a21\u677f\u6587\u4ef6\u5939\u6765\u521b\u5efa\u89c4\u5219\u6587\u4ef6\u3002<br \/>\n\u30fb\u652f\u6301Kibana 7.2.0\uff5e7.5.0\u7248\u672c\u3002<br \/>\n\u30fb\u5efa\u8bae\u4e0d\u4e0ePraeco\u4e00\u8d77\u4f7f\u7528\u3002<br \/>\n\uff1c\u539f\u56e0\uff1e<br \/>\n\u5982\u679c\u4f7f\u7528\u4e86Praeco\u4e0d\u652f\u6301\u7684\u8bbe\u7f6e\u8fdb\u884c\u7f16\u8f91\uff0c\u5f53\u5728Praeco\u4e2d\u66f4\u6539\u4e86\u8b66\u62a5\u89c4\u5219\u7684\u542f\u7528\/\u7981\u7528\u65f6\uff0c\u7f16\u5199\u7684\u8bbe\u7f6e\u4f1a\u6d88\u5931\u3002<br \/>\n\u9700\u8981\u6ce8\u610f\u7684\u662f\uff0c\u8fd9\u79cd\u884c\u4e3a\u662f\u7531\u4f7f\u7528\u8005\u9519\u8bef\u7684\u4f7f\u7528\u65b9\u5f0f\u5f15\u8d77\u7684\uff0c\u5e76\u4e14\u6211\u8ba4\u4e3a\u8fd9\u662f\u4e00\u4e2a\u8bbe\u8ba1\u89c4\u8303\u3002<\/p>\n<h4>\u5bf9\u4e8eElastAlert Kibana\u63d2\u4ef6\u7684\u60f3\u6cd5<\/h4>\n<p>\u7531\u4e8e\u6700\u65b0\u7248\u672c\u7684Kibana\u65e0\u6cd5\u4f7f\u7528\uff08\u5b98\u65b9\u53ea\u652f\u6301\u5230Kibana 7.5.0\uff09\uff0c\u6240\u4ee5\u65e0\u6cd5\u63a8\u8350\u91c7\u7528\u3002<br \/>\n\u5982\u679c\u80fd\u591f\u8fdb\u884c\u6539\u8fdb\uff0c\u4ee5\u786e\u4fdd\u5c06\u6765\u4e0d\u4f1a\u51fa\u73b0\u65e0\u6cd5\u8fd0\u884c\u7684\u60c5\u51b5\uff0c\u6211\u8ba4\u4e3a\u53ef\u4ee5\u8003\u8651\u91c7\u7528\u6700\u65b0\u7248\u672c\u7684Kibana\u3002<\/p>\n<h4>Kibana\u7684\u7248\u672c\u8303\u56f4\u53ef\u4ee5\u4ece6.8.1\u52306.8.10\u30017.5.1\u52307.9.3\uff0c\u4ee5\u53ca7.10.0\u52308.5.3\u3002<\/h4>\n<p>Kibana\u63d2\u4ef6\u652f\u6301\u7248\u672c\u8303\u56f4\u4e3a7.10.0\uff5e8.5.3\u3002<br \/>\n\u94fe\u63a5\u5730\u5740\u4e3a\uff1ahttps:\/\/github.com\/karql\/elastalert-kibana-plugin\u3002<br \/>\nKibana\u63d2\u4ef6\u8fd8\u517c\u5bb9\u7684\u7248\u672c\u67096.8.1\uff5e6.8.10\u30017.5.1\uff5e7.9.3\u3002<br \/>\n\u94fe\u63a5\u5730\u5740\u4e3a\uff1ahttps:\/\/github.com\/nsano-rururu\/elastalert-kibana-plugin\/releases\u3002<\/p>\n<h3>Kibana 6.8.x \u5728\u4e2d\u6587\u73af\u5883\u4e0b\u4e5f\u53ef\u8fd0\u884c\u5417\uff1f<\/h3>\n<p>\u65e0\u6cd5\u5b89\u88c5elastalert-kibana-plugin-1.0.3-6.8.0.zip\u5230Kibana 6.8.3 #123<\/p>\n<h4>Kibana\u7684\u7248\u672c\u4ece7.5.1\u52307.8.1\u53ef\u8fd0\u884c\u3002<\/h4>\n<p>\u4e0b\u8f7delastalert-kibana-plugin-1.1.0-7.5.0.zip\uff0c\u5e76\u66f4\u65b0kibana\/elastalert-kibana-plugin\/package.json\u4e2d\u7684Kibana\u7248\u672c\uff0c\u7136\u540e\u5c06\u5176\u538b\u7f29\u4e3azip\u6587\u4ef6\u3002\u8fd9\u6837\u53ef\u4ee5\u5728Kibana 7.5.1\u548c7.5.2\u4e0a\u8fd0\u884c\u3002\u5bf9\u4e8eKibana 7.6.0\uff5e7.8.1\uff0c\u9664\u4e86\u66f4\u65b0package.json\u4e2d\u7684Kibana\u7248\u672c\u5916\uff0c\u8fd8\u9700\u8981\u66ff\u6362elastalert.js\u6587\u4ef6\u3002<\/p>\n<p>\u5f39\u6027\u8b66\u62a5-Kibana\u63d2\u4ef6[7.5.0]\u4e0eKibana[7.5.1]\u4e0d\u517c\u5bb9\uff03139<br \/>\n\u63d2\u4ef6\u4e0eKibana 7.6.0\u4e0d\u517c\u5bb9\uff03141<br \/>\n[\u9057\u7559]\u5f53\u542f\u7528\u6709\u6548\u8d1f\u8f7d\u9a8c\u8bc1\u65f6\uff0c\u8def\u7531\u8d1f\u8f7d\u5fc5\u987b\u8bbe\u7f6e\u4e3a&#8217;parse&#8217;\uff0357777<br \/>\n\u66f4\u65b0Elasticsearch\u52307.6.2\uff1b\u53e6\u5916\uff0c\u4fee\u590d\u95ee\u9898idaholab\uff03119<\/p>\n<h4>\u5982\u679c\u8981\u521b\u5efa\u4e00\u4e2a\u5305\u542bElastAlert\u63d2\u4ef6\u7684Docker\u955c\u50cf\u5e76\u5728Kibana\u4e2d\u5b89\u88c5\u7684\u60c5\u51b5\u4e0b<\/h4>\n<p>\u6211\u5df2\u7ecf\u64b0\u5199\u4e86\u4e00\u7bc7\u5173\u4e8e\u521b\u5efaKibana 7.5.1\uff5e7.8.1 Docker\u955c\u50cf\u7684\u65b9\u6cd5\u7684\u6587\u7ae0\uff0c\u5e76\u5305\u62ec\u5b89\u88c5elastalert-kibana-plugin\u7684\u6b65\u9aa4\u3002<\/p>\n<h4>\u5982\u679c\u8981\u5728docker-compose\u7684\u547d\u4ee4\u4e2d\u5b89\u88c5ElastAlert\u63d2\u4ef6\uff0c\u8bf7\u4f7f\u7528\u4ee5\u4e0b\u9009\u9879\u3002<\/h4>\n<pre class=\"post-pre\"><code># (\u53c2\u8003\u60c5\u5831)elastalert-kibana-plugin-1.1.0-7.5.1.zip\u4f5c\u6210\r\ncd \/tmp\r\ncurl -L -O https:\/\/github.com\/bitsensor\/elastalert-kibana-plugin\/releases\/download\/1.1.0\/elastalert-kibana-plugin-1.1.0-7.5.0.zip\r\nmv elastalert-kibana-plugin-1.1.0-7.5.0.zip elastalert-kibana-plugin-1.1.0-7.5.1.zip\r\nunzip elastalert-kibana-plugin-1.1.0-7.5.1.zip kibana\/elastalert-kibana-plugin\/package.json\r\nsed -i \"s\/7\\.5\\.0\/7\\.5\\.1\/g\" kibana\/elastalert-kibana-plugin\/package.json\r\nzip elastalert-kibana-plugin-1.1.0-7.5.1.zip kibana\/elastalert-kibana-plugin\/package.json\r\nrm -rf kibana\r\n\r\n# elastalert-kibana-plugin-1.1.0-7.5.2.zip\u4f5c\u6210\r\ncd \/tmp\r\ncurl -L -O https:\/\/github.com\/bitsensor\/elastalert-kibana-plugin\/releases\/download\/1.1.0\/elastalert-kibana-plugin-1.1.0-7.5.0.zip\r\nmv elastalert-kibana-plugin-1.1.0-7.5.0.zip elastalert-kibana-plugin-1.1.0-7.5.2.zip\r\nunzip elastalert-kibana-plugin-1.1.0-7.5.2.zip kibana\/elastalert-kibana-plugin\/package.json\r\nsed -i \"s\/7\\.5\\.0\/7\\.5\\.2\/g\" kibana\/elastalert-kibana-plugin\/package.json\r\nzip elastalert-kibana-plugin-1.1.0-7.5.2.zip kibana\/elastalert-kibana-plugin\/package.json\r\nrm -rf kibana\r\n\r\n# (\u53c2\u8003\u60c5\u5831)elastalert-kibana-plugin-1.1.0-7.6.0.zip\u4f5c\u6210\r\ncd \/tmp\r\ncurl -L -O https:\/\/github.com\/bitsensor\/elastalert-kibana-plugin\/releases\/download\/1.1.0\/elastalert-kibana-plugin-1.1.0-7.5.0.zip\r\n# [update elasticsearch to 7.6.2; also, fix issue idaholab#119](https:\/\/github.com\/mmguero-dev\/Malcolm\/commit\/b38ddb7f0d4c5b03e6f8ccad58a656644e113b19)\r\ncurl -L -O https:\/\/raw.githubusercontent.com\/mmguero-dev\/Malcolm\/development\/kibana\/elastalert-kibana-plugin\/server\/routes\/elastalert.js\r\nmv elastalert.js elastalert-server-routes.js\r\nmv elastalert-kibana-plugin-1.1.0-7.5.0.zip elastalert-kibana-plugin-1.1.0-7.6.0.zip\r\nunzip elastalert-kibana-plugin-1.1.0-7.6.0.zip kibana\/elastalert-kibana-plugin\/package.json\r\nsed -i \"s\/7\\.5\\.0\/7\\.6\\.0\/g\" kibana\/elastalert-kibana-plugin\/package.json\r\nmkdir -p kibana\/elastalert-kibana-plugin\/server\/routes\/\r\ncp \/tmp\/elastalert-server-routes.js kibana\/elastalert-kibana-plugin\/server\/routes\/elastalert.js\r\nzip elastalert-kibana-plugin-1.1.0-7.6.0.zip kibana\/elastalert-kibana-plugin\/package.json kibana\/elastalert-kibana-plugin\/server\/routes\/elastalert.js\r\nrm -rf kibana\r\nrm elastalert-server-routes.js\r\n\r\n# (\u53c2\u8003\u60c5\u5831)elastalert-kibana-plugin-1.1.0-7.6.1.zip\u4f5c\u6210\r\ncd \/tmp\r\ncurl -L -O https:\/\/github.com\/bitsensor\/elastalert-kibana-plugin\/releases\/download\/1.1.0\/elastalert-kibana-plugin-1.1.0-7.5.0.zip\r\n# [update elasticsearch to 7.6.2; also, fix issue idaholab#119](https:\/\/github.com\/mmguero-dev\/Malcolm\/commit\/b38ddb7f0d4c5b03e6f8ccad58a656644e113b19)\r\ncurl -L -O https:\/\/raw.githubusercontent.com\/mmguero-dev\/Malcolm\/development\/kibana\/elastalert-kibana-plugin\/server\/routes\/elastalert.js\r\nmv elastalert.js elastalert-server-routes.js\r\nmv elastalert-kibana-plugin-1.1.0-7.5.0.zip elastalert-kibana-plugin-1.1.0-7.6.1.zip\r\nunzip elastalert-kibana-plugin-1.1.0-7.6.1.zip kibana\/elastalert-kibana-plugin\/package.json\r\nsed -i \"s\/7\\.5\\.0\/7\\.6\\.1\/g\" kibana\/elastalert-kibana-plugin\/package.json\r\nmkdir -p kibana\/elastalert-kibana-plugin\/server\/routes\/\r\ncp \/tmp\/elastalert-server-routes.js kibana\/elastalert-kibana-plugin\/server\/routes\/elastalert.js\r\nzip elastalert-kibana-plugin-1.1.0-7.6.1.zip kibana\/elastalert-kibana-plugin\/package.json kibana\/elastalert-kibana-plugin\/server\/routes\/elastalert.js\r\nrm -rf kibana\r\nrm elastalert-server-routes.js\r\n\r\n# (\u53c2\u8003\u60c5\u5831)elastalert-kibana-plugin-1.1.0-7.6.2.zip\u4f5c\u6210\r\ncd \/tmp\r\ncurl -L -O https:\/\/github.com\/bitsensor\/elastalert-kibana-plugin\/releases\/download\/1.1.0\/elastalert-kibana-plugin-1.1.0-7.5.0.zip\r\n# [update elasticsearch to 7.6.2; also, fix issue idaholab#119](https:\/\/github.com\/mmguero-dev\/Malcolm\/commit\/b38ddb7f0d4c5b03e6f8ccad58a656644e113b19)\r\ncurl -L -O https:\/\/raw.githubusercontent.com\/mmguero-dev\/Malcolm\/development\/kibana\/elastalert-kibana-plugin\/server\/routes\/elastalert.js\r\nmv elastalert.js elastalert-server-routes.js\r\nmv elastalert-kibana-plugin-1.1.0-7.5.0.zip elastalert-kibana-plugin-1.1.0-7.6.2.zip\r\nunzip elastalert-kibana-plugin-1.1.0-7.6.2.zip kibana\/elastalert-kibana-plugin\/package.json\r\nsed -i \"s\/7\\.5\\.0\/7\\.6\\.2\/g\" kibana\/elastalert-kibana-plugin\/package.json\r\nmkdir -p kibana\/elastalert-kibana-plugin\/server\/routes\/\r\ncp \/tmp\/elastalert-server-routes.js kibana\/elastalert-kibana-plugin\/server\/routes\/elastalert.js\r\nzip elastalert-kibana-plugin-1.1.0-7.6.2.zip kibana\/elastalert-kibana-plugin\/package.json kibana\/elastalert-kibana-plugin\/server\/routes\/elastalert.js\r\nrm -rf kibana\r\nrm elastalert-server-routes.js\r\n\r\n# (\u53c2\u8003\u60c5\u5831)elastalert-kibana-plugin-1.1.0-7.7.0.zip\u4f5c\u6210\r\ncd \/tmp\r\ncurl -L -O https:\/\/github.com\/bitsensor\/elastalert-kibana-plugin\/releases\/download\/1.1.0\/elastalert-kibana-plugin-1.1.0-7.5.0.zip\r\n# [update elasticsearch to 7.7.0; also, fix issue idaholab#119](https:\/\/github.com\/mmguero-dev\/Malcolm\/commit\/b38ddb7f0d4c5b03e6f8ccad58a656644e113b19)\r\ncurl -L -O https:\/\/raw.githubusercontent.com\/mmguero-dev\/Malcolm\/development\/kibana\/elastalert-kibana-plugin\/server\/routes\/elastalert.js\r\nmv elastalert.js elastalert-server-routes.js\r\nmv elastalert-kibana-plugin-1.1.0-7.5.0.zip elastalert-kibana-plugin-1.1.0-7.7.0.zip\r\nunzip elastalert-kibana-plugin-1.1.0-7.7.0.zip kibana\/elastalert-kibana-plugin\/package.json\r\nsed -i \"s\/7\\.5\\.0\/7\\.7\\.0\/g\" kibana\/elastalert-kibana-plugin\/package.json\r\nmkdir -p kibana\/elastalert-kibana-plugin\/server\/routes\/\r\ncp \/tmp\/elastalert-server-routes.js kibana\/elastalert-kibana-plugin\/server\/routes\/elastalert.js\r\nzip elastalert-kibana-plugin-1.1.0-7.7.0.zip kibana\/elastalert-kibana-plugin\/package.json kibana\/elastalert-kibana-plugin\/server\/routes\/elastalert.js\r\nrm -rf kibana\r\nrm elastalert-server-routes.js\r\n\r\n# (\u53c2\u8003\u60c5\u5831)elastalert-kibana-plugin-1.1.0-7.7.1.zip\u4f5c\u6210\r\ncd \/tmp\r\ncurl -L -O https:\/\/github.com\/bitsensor\/elastalert-kibana-plugin\/releases\/download\/1.1.0\/elastalert-kibana-plugin-1.1.0-7.5.0.zip\r\n# [update elasticsearch to 7.7.1; also, fix issue idaholab#119](https:\/\/github.com\/mmguero-dev\/Malcolm\/commit\/b38ddb7f0d4c5b03e6f8ccad58a656644e113b19)\r\ncurl -L -O https:\/\/raw.githubusercontent.com\/mmguero-dev\/Malcolm\/development\/kibana\/elastalert-kibana-plugin\/server\/routes\/elastalert.js\r\nmv elastalert.js elastalert-server-routes.js\r\nmv elastalert-kibana-plugin-1.1.0-7.5.0.zip elastalert-kibana-plugin-1.1.0-7.7.1.zip\r\nunzip elastalert-kibana-plugin-1.1.0-7.7.1.zip kibana\/elastalert-kibana-plugin\/package.json\r\nsed -i \"s\/7\\.5\\.0\/7\\.7\\.1\/g\" kibana\/elastalert-kibana-plugin\/package.json\r\nmkdir -p kibana\/elastalert-kibana-plugin\/server\/routes\/\r\ncp \/tmp\/elastalert-server-routes.js kibana\/elastalert-kibana-plugin\/server\/routes\/elastalert.js\r\nzip elastalert-kibana-plugin-1.1.0-7.7.1.zip kibana\/elastalert-kibana-plugin\/package.json kibana\/elastalert-kibana-plugin\/server\/routes\/elastalert.js\r\nrm -rf kibana\r\nrm elastalert-server-routes.js\r\n\r\n# (\u53c2\u8003\u60c5\u5831)elastalert-kibana-plugin-1.1.0-7.8.0.zip\u4f5c\u6210\r\ncd \/tmp\r\ncurl -L -O https:\/\/github.com\/bitsensor\/elastalert-kibana-plugin\/releases\/download\/1.1.0\/elastalert-kibana-plugin-1.1.0-7.5.0.zip\r\n# [update elasticsearch to 7.8.0; also, fix issue idaholab#119](https:\/\/github.com\/mmguero-dev\/Malcolm\/commit\/b38ddb7f0d4c5b03e6f8ccad58a656644e113b19)\r\ncurl -L -O https:\/\/raw.githubusercontent.com\/mmguero-dev\/Malcolm\/development\/kibana\/elastalert-kibana-plugin\/server\/routes\/elastalert.js\r\nmv elastalert.js elastalert-server-routes.js\r\nmv elastalert-kibana-plugin-1.1.0-7.5.0.zip elastalert-kibana-plugin-1.1.0-7.8.0.zip\r\nunzip elastalert-kibana-plugin-1.1.0-7.8.0.zip kibana\/elastalert-kibana-plugin\/package.json\r\nsed -i \"s\/7\\.5\\.0\/7\\.8\\.0\/g\" kibana\/elastalert-kibana-plugin\/package.json\r\nmkdir -p kibana\/elastalert-kibana-plugin\/server\/routes\/\r\ncp \/tmp\/elastalert-server-routes.js kibana\/elastalert-kibana-plugin\/server\/routes\/elastalert.js\r\nzip elastalert-kibana-plugin-1.1.0-7.8.0.zip kibana\/elastalert-kibana-plugin\/package.json kibana\/elastalert-kibana-plugin\/server\/routes\/elastalert.js\r\nrm -rf kibana\r\nrm elastalert-server-routes.js\r\n<\/code><\/pre>\n<h4>\u76ee\u5f55\u7ed3\u6784<\/h4>\n<p>\u5c06\u4ee5\u4e0b\u5185\u5bb9\u8fdb\u884c\u4e2d\u56fd\u672c\u5730\u5316\u5e76\u6539\u5199\u4e3a\u4e2d\u6587\uff0c\u53ea\u9700\u8981\u4e00\u4e2a\u9009\u9879\uff1a<br \/>\n&#8220;.\/elastalert\/rules&#8221;\u3001&#8221;.\/elastalert\/rule_templates&#8221;\u3001&#8221;.\/es\/data&#8221; \u53ef\u4ee5\u4f7f\u7528 chmod \u547d\u4ee4\u8bbe\u7f6e\u4e3a 777 \u6743\u9650\u3002<\/p>\n<p>ElastAlert\u7684\u6587\u4ef6\u4f7f\u7528\u4ee5\u4e0b\u7f51\u7ad9\u4e0a\u7684\u6587\u4ef6\u3002\u4fee\u6539\u90e8\u5206\u503c\u3002<br \/>\nhttps:\/\/github.com\/bitsensor\/elastalert<\/p>\n<pre class=\"post-pre\"><code>\/home\/\u30e6\u30fc\u30b6\u30fc\u540d\/dkwork\/es\/\r\n|--docker-compose.yml\r\n|--Dockerfiles\r\n|  |--Dockerfile.elastalert\r\n|\r\n|--es\r\n|  |--config\r\n|  |  |--elasticsearch.yml\r\n|  |--data\r\n|\r\n|--kibana\r\n|  |--config\r\n|  |  |--kibana.yml\r\n|  |--plugin\r\n|  |  |--elastalert-kibana-plugin-1.1.0-7.7.0.zip\r\n|\r\n|--elastalert\r\n|  |--bin\r\n|  |  |--elastalert-start.sh\r\n|  |  |--elastic_search_status.sh\r\n|  |--config\r\n|  |  |--config.json\r\n|  |  |--elastalert-test.yaml\r\n|  |  |--elastalert.yaml\r\n|  |--rule_templates\r\n|  |--rules\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"na\">version<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">3.7\"<\/span>\r\n<span class=\"na\">services<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">elasticsearch<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">container_name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">elasticsearch<\/span>\r\n    <span class=\"na\">image<\/span><span class=\"pi\">:<\/span> <span class=\"s\">docker.elastic.co\/elasticsearch\/elasticsearch:7.7.0<\/span>\r\n    <span class=\"na\">ports<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">9200:9200<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">9300:9300<\/span>\r\n    <span class=\"na\">environment<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">ES_JAVA_OPTS=-Xms256m -Xmx512m<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">discovery.type=single-node<\/span>\r\n    <span class=\"na\">restart<\/span><span class=\"pi\">:<\/span> <span class=\"s\">always<\/span>\r\n    <span class=\"na\">volumes<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">.\/es\/data:\/usr\/share\/elasticsearch\/data<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">.\/es\/config\/elasticsearch.yml:\/usr\/share\/elasticsearch\/config\/elasticsearch.yml<\/span>\r\n    <span class=\"na\">healthcheck<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"na\">test<\/span><span class=\"pi\">:<\/span> <span class=\"pi\">[<\/span><span class=\"s2\">\"<\/span><span class=\"s\">CMD-SHELL\"<\/span><span class=\"pi\">,<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">curl<\/span> <span class=\"s\">-f<\/span> <span class=\"s\">http:\/\/localhost:9200<\/span> <span class=\"s\">||<\/span> <span class=\"s\">exit<\/span> <span class=\"s\">1\"<\/span><span class=\"pi\">]<\/span>\r\n        <span class=\"na\">interval<\/span><span class=\"pi\">:<\/span> <span class=\"s\">30s<\/span>\r\n        <span class=\"na\">timeout<\/span><span class=\"pi\">:<\/span> <span class=\"s\">15s<\/span>\r\n        <span class=\"na\">retries<\/span><span class=\"pi\">:<\/span> <span class=\"m\">3<\/span>\r\n        <span class=\"na\">start_period<\/span><span class=\"pi\">:<\/span> <span class=\"s\">180s<\/span>\r\n\r\n  <span class=\"na\">kibana<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">container_name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">kibana<\/span>\r\n    <span class=\"na\">image<\/span><span class=\"pi\">:<\/span> <span class=\"s\">docker.elastic.co\/kibana\/kibana:7.7.0<\/span>\r\n    <span class=\"na\">command<\/span><span class=\"pi\">:<\/span> <span class=\"s\">sh -c '.\/bin\/kibana-plugin list | grep elastalert-kibana-plugin@1.1.0; result=`echo $$?`; if [ $$result = 1 ]; then  .\/bin\/kibana-plugin install file:\/\/\/usr\/share\/kibana\/work\/elastalert-kibana-plugin-1.1.0-7.7.0.zip &amp;&amp; exec \/usr\/local\/bin\/kibana-docker; else exec \/usr\/local\/bin\/kibana-docker; fi'<\/span>\r\n    <span class=\"na\">ports<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">5601:5601<\/span>\r\n    <span class=\"na\">depends_on<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">elasticsearch<\/span>\r\n    <span class=\"na\">restart<\/span><span class=\"pi\">:<\/span> <span class=\"s\">always<\/span>\r\n    <span class=\"na\">volumes<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">.\/kibana\/config\/kibana.yml:\/usr\/share\/kibana\/config\/kibana.yml<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">.\/kibana\/plugin:\/usr\/share\/kibana\/work<\/span>\r\n    <span class=\"na\">healthcheck<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"na\">test<\/span><span class=\"pi\">:<\/span> <span class=\"pi\">[<\/span><span class=\"s2\">\"<\/span><span class=\"s\">CMD-SHELL\"<\/span><span class=\"pi\">,<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">curl<\/span> <span class=\"s\">-f<\/span> <span class=\"s\">http:\/\/localhost:5601\/api\/status<\/span> <span class=\"s\">||<\/span> <span class=\"s\">exit<\/span> <span class=\"s\">1\"<\/span><span class=\"pi\">]<\/span>\r\n        <span class=\"na\">interval<\/span><span class=\"pi\">:<\/span> <span class=\"s\">30s<\/span>\r\n        <span class=\"na\">timeout<\/span><span class=\"pi\">:<\/span> <span class=\"s\">15s<\/span>\r\n        <span class=\"na\">retries<\/span><span class=\"pi\">:<\/span> <span class=\"m\">3<\/span>\r\n        <span class=\"na\">start_period<\/span><span class=\"pi\">:<\/span> <span class=\"s\">200s<\/span>\r\n        \r\n  <span class=\"na\">elastalert<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">container_name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">elastalert<\/span>\r\n    <span class=\"na\">build<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">context<\/span><span class=\"pi\">:<\/span> <span class=\"s\">.<\/span>\r\n      <span class=\"na\">dockerfile<\/span><span class=\"pi\">:<\/span> <span class=\"s\">Dockerfiles\/Dockerfile.elastalert<\/span>\r\n    <span class=\"na\">image<\/span><span class=\"pi\">:<\/span> <span class=\"s\">elastalert:3.0.0-beta.0<\/span>\r\n    <span class=\"na\">ports<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">3030:3030<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">3333:3333<\/span>\r\n    <span class=\"na\">depends_on<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">elasticsearch<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">kibana<\/span>\r\n    <span class=\"na\">restart<\/span><span class=\"pi\">:<\/span> <span class=\"s\">always<\/span>\r\n    <span class=\"na\">volumes<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">.\/elastalert\/config\/elastalert.yaml:\/opt\/elastalert\/config.yaml<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">.\/elastalert\/config\/elastalert-test.yaml:\/opt\/elastalert\/config-test.yaml<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">.\/elastalert\/config\/config.json:\/opt\/elastalert-server\/config\/config.json<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">.\/elastalert\/rules:\/opt\/elastalert\/rules<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">.\/elastalert\/rule_templates:\/opt\/elastalert\/rule_templates<\/span>\r\n    <span class=\"na\">healthcheck<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"na\">test<\/span><span class=\"pi\">:<\/span> <span class=\"pi\">[<\/span><span class=\"s2\">\"<\/span><span class=\"s\">CMD-SHELL\"<\/span><span class=\"pi\">,<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">curl<\/span> <span class=\"s\">-f<\/span> <span class=\"s\">http:\/\/localhost:3030<\/span> <span class=\"s\">||<\/span> <span class=\"s\">exit<\/span> <span class=\"s\">1\"<\/span><span class=\"pi\">]<\/span>\r\n        <span class=\"na\">interval<\/span><span class=\"pi\">:<\/span> <span class=\"s\">30s<\/span>\r\n        <span class=\"na\">timeout<\/span><span class=\"pi\">:<\/span> <span class=\"s\">15s<\/span>\r\n        <span class=\"na\">retries<\/span><span class=\"pi\">:<\/span> <span class=\"m\">3<\/span>\r\n        <span class=\"na\">start_period<\/span><span class=\"pi\">:<\/span> <span class=\"s\">200s<\/span>\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code>FROM bitsensor\/elastalert:3.0.0-beta.0\r\n\r\nUSER root\r\n\r\nRUN apk update &amp;&amp; \\\r\n    apk add bash curl &amp;&amp; \\\r\n    rm -rf \/var\/cache\/apk\/*\r\n\r\nADD elastalert\/bin\/elastalert-start.sh \/usr\/local\/bin\/\r\nADD elastalert\/bin\/elastic_search_status.sh \/usr\/local\/bin\/\r\n\r\nRUN chmod +x \/usr\/local\/bin\/elastalert-start.sh \r\nRUN chmod +x \/usr\/local\/bin\/elastic_search_status.sh\r\n\r\nUSER node\r\n\r\nENTRYPOINT [\"\/usr\/local\/bin\/elastalert-start.sh\"]\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"c\">#!\/bin\/bash<\/span>\r\n\r\n<span class=\"nb\">set<\/span> <span class=\"nt\">-e<\/span>\r\n\r\n<span class=\"k\">if<\/span> <span class=\"o\">[<\/span> <span class=\"nv\">$# <\/span><span class=\"nt\">-gt<\/span> 0 <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n  <\/span><span class=\"nv\">ES_URL<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"<\/span><span class=\"nv\">$1<\/span><span class=\"s2\">\"<\/span>\r\n<span class=\"k\">elif<\/span> <span class=\"o\">[[<\/span> <span class=\"nt\">-n<\/span> <span class=\"nv\">$ELASTICSEARCH_URL<\/span> <span class=\"o\">]]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n  <\/span><span class=\"nv\">ES_URL<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"<\/span><span class=\"nv\">$ELASTICSEARCH_URL<\/span><span class=\"s2\">\"<\/span>\r\n<span class=\"k\">elif<\/span> <span class=\"o\">[[<\/span> <span class=\"nt\">-n<\/span> <span class=\"nv\">$ES_HOST<\/span> <span class=\"o\">]]<\/span> <span class=\"o\">&amp;&amp;<\/span> <span class=\"o\">[[<\/span> <span class=\"nt\">-n<\/span> <span class=\"nv\">$ES_PORT<\/span> <span class=\"o\">]]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n  <\/span><span class=\"nv\">ES_URL<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"http:\/\/<\/span><span class=\"nv\">$ES_HOST<\/span><span class=\"s2\">:<\/span><span class=\"nv\">$ES_PORT<\/span><span class=\"s2\">\"<\/span>\r\n<span class=\"k\">else\r\n  <\/span><span class=\"nv\">ES_URL<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"http:\/\/elasticsearch:9200\"<\/span>\r\n<span class=\"k\">fi\r\n\r\nuntil<\/span> <span class=\"o\">[[<\/span> <span class=\"s2\">\"<\/span><span class=\"si\">$(<\/span>curl <span class=\"nt\">-fsSL<\/span> <span class=\"s2\">\"<\/span><span class=\"nv\">$ES_URL<\/span><span class=\"s2\">\/_cat\/health?h=status\"<\/span> | <span class=\"nb\">sed<\/span> <span class=\"nt\">-r<\/span> <span class=\"s1\">'s\/^[[:space:]]+|[[:space:]]+$\/\/g'<\/span><span class=\"si\">)<\/span><span class=\"s2\">\"<\/span> <span class=\"o\">=<\/span>~ ^<span class=\"o\">(<\/span>yellow|green<span class=\"o\">)<\/span><span class=\"nv\">$ <\/span><span class=\"o\">]]<\/span><span class=\"p\">;<\/span> <span class=\"k\">do<\/span>\r\n  <span class=\"c\"># printf '+' &gt;&amp;2<\/span>\r\n  <span class=\"nb\">sleep <\/span>1\r\n<span class=\"k\">done\r\n\r\n<\/span><span class=\"nb\">echo<\/span> <span class=\"s2\">\"Elasticsearch is up and healthy at \"<\/span><span class=\"nv\">$ES_URL<\/span><span class=\"s2\">\"\"<\/span> <span class=\"o\">&gt;<\/span>&amp;2\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"c\">#!\/bin\/bash<\/span>\r\n\r\n<span class=\"nb\">set<\/span> <span class=\"nt\">-e<\/span>\r\n\r\n<span class=\"nb\">echo<\/span> <span class=\"s2\">\"Giving Elasticsearch at <\/span><span class=\"nv\">$ELASTICSEARCH_URL<\/span><span class=\"s2\"> time to start...\"<\/span>\r\n\r\nelastic_search_status.sh\r\n\r\n<span class=\"nb\">echo<\/span> <span class=\"s2\">\"Starting ElastAlert!\"<\/span>\r\nnpm start\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"na\">cluster.name<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">docker-cluster\"<\/span>\r\n<span class=\"na\">network.host<\/span><span class=\"pi\">:<\/span> <span class=\"s\">0.0.0.0<\/span>\r\n<span class=\"na\">discovery.zen.minimum_master_nodes<\/span><span class=\"pi\">:<\/span> <span class=\"m\">1<\/span>\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"na\">server.name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">kibana<\/span>\r\n<span class=\"na\">server.host<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">0\"<\/span>\r\n<span class=\"na\">elasticsearch.hosts<\/span><span class=\"pi\">:<\/span> <span class=\"s\">http:\/\/elasticsearch:9200<\/span>\r\n<span class=\"na\">xpack.monitoring.ui.container.elasticsearch.enabled<\/span><span class=\"pi\">:<\/span> <span class=\"kc\">true<\/span>\r\n\r\n<span class=\"c1\"># elastalert-kibana-plugin<\/span>\r\n<span class=\"na\">elastalert-kibana-plugin.serverHost<\/span><span class=\"pi\">:<\/span> <span class=\"s\">elastalert<\/span>\r\n<span class=\"na\">elastalert-kibana-plugin.serverPort<\/span><span class=\"pi\">:<\/span> <span class=\"m\">3030<\/span>\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"p\">{<\/span>\r\n  <span class=\"nl\">\"appName\"<\/span><span class=\"p\">:<\/span> <span class=\"s2\">\"elastalert-server\"<\/span><span class=\"p\">,<\/span>\r\n  <span class=\"nl\">\"port\"<\/span><span class=\"p\">:<\/span> <span class=\"mi\">3030<\/span><span class=\"p\">,<\/span>\r\n  <span class=\"nl\">\"wsport\"<\/span><span class=\"p\">:<\/span> <span class=\"mi\">3333<\/span><span class=\"p\">,<\/span>\r\n  <span class=\"nl\">\"elastalertPath\"<\/span><span class=\"p\">:<\/span> <span class=\"s2\">\"\/opt\/elastalert\"<\/span><span class=\"p\">,<\/span>\r\n  <span class=\"nl\">\"verbose\"<\/span><span class=\"p\">:<\/span> <span class=\"kc\">false<\/span><span class=\"p\">,<\/span>\r\n  <span class=\"nl\">\"es_debug\"<\/span><span class=\"p\">:<\/span> <span class=\"kc\">false<\/span><span class=\"p\">,<\/span>\r\n  <span class=\"nl\">\"debug\"<\/span><span class=\"p\">:<\/span> <span class=\"kc\">false<\/span><span class=\"p\">,<\/span>\r\n  <span class=\"nl\">\"rulesPath\"<\/span><span class=\"p\">:<\/span> <span class=\"p\">{<\/span>\r\n    <span class=\"nl\">\"relative\"<\/span><span class=\"p\">:<\/span> <span class=\"kc\">true<\/span><span class=\"p\">,<\/span>\r\n    <span class=\"nl\">\"path\"<\/span><span class=\"p\">:<\/span> <span class=\"s2\">\"\/rules\"<\/span>\r\n  <span class=\"p\">},<\/span>\r\n  <span class=\"nl\">\"templatesPath\"<\/span><span class=\"p\">:<\/span> <span class=\"p\">{<\/span>\r\n    <span class=\"nl\">\"relative\"<\/span><span class=\"p\">:<\/span> <span class=\"kc\">true<\/span><span class=\"p\">,<\/span>\r\n    <span class=\"nl\">\"path\"<\/span><span class=\"p\">:<\/span> <span class=\"s2\">\"\/rule_templates\"<\/span>\r\n  <span class=\"p\">},<\/span>\r\n  <span class=\"nl\">\"es_host\"<\/span><span class=\"p\">:<\/span> <span class=\"s2\">\"elasticsearch\"<\/span><span class=\"p\">,<\/span>\r\n  <span class=\"nl\">\"es_port\"<\/span><span class=\"p\">:<\/span> <span class=\"mi\">9200<\/span><span class=\"p\">,<\/span>\r\n  <span class=\"nl\">\"writeback_index\"<\/span><span class=\"p\">:<\/span> <span class=\"s2\">\"elastalert_status\"<\/span>\r\n<span class=\"p\">}<\/span>\r\n<\/code><\/pre>\n<p>\u5c06 es_host \u7684\u503c\u4ece &#8220;localhost&#8221; \u66f4\u6539\u4e3a &#8220;elasticsearch&#8221;\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"c1\"># NOTE: This config is used when testing a rule<\/span>\r\n\r\n<span class=\"c1\"># The elasticsearch hostname for metadata writeback<\/span>\r\n<span class=\"c1\"># Note that every rule can have its own elasticsearch host<\/span>\r\n<span class=\"na\">es_host<\/span><span class=\"pi\">:<\/span> <span class=\"s\">elasticsearch<\/span>\r\n\r\n<span class=\"c1\"># The elasticsearch port<\/span>\r\n<span class=\"na\">es_port<\/span><span class=\"pi\">:<\/span> <span class=\"m\">9200<\/span>\r\n\r\n<span class=\"c1\"># This is the folder that contains the rule yaml files<\/span>\r\n<span class=\"c1\"># Any .yaml file will be loaded as a rule<\/span>\r\n<span class=\"na\">rules_folder<\/span><span class=\"pi\">:<\/span> <span class=\"s\">rules<\/span>\r\n\r\n<span class=\"c1\"># How often ElastAlert will query elasticsearch<\/span>\r\n<span class=\"c1\"># The unit can be anything from weeks to seconds<\/span>\r\n<span class=\"na\">run_every<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">seconds<\/span><span class=\"pi\">:<\/span> <span class=\"m\">5<\/span>\r\n\r\n<span class=\"c1\"># ElastAlert will buffer results from the most recent<\/span>\r\n<span class=\"c1\"># period of time, in case some log sources are not in real time<\/span>\r\n<span class=\"na\">buffer_time<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">minutes<\/span><span class=\"pi\">:<\/span> <span class=\"m\">1<\/span>\r\n\r\n<span class=\"c1\"># Optional URL prefix for elasticsearch<\/span>\r\n<span class=\"c1\">#es_url_prefix: elasticsearch<\/span>\r\n\r\n<span class=\"c1\"># Connect with TLS to elasticsearch<\/span>\r\n<span class=\"c1\">#use_ssl: True<\/span>\r\n\r\n<span class=\"c1\"># Verify TLS certificates<\/span>\r\n<span class=\"c1\">#verify_certs: True<\/span>\r\n\r\n<span class=\"c1\"># GET request with body is the default option for Elasticsearch.<\/span>\r\n<span class=\"c1\"># If it fails for some reason, you can pass 'GET', 'POST' or 'source'.<\/span>\r\n<span class=\"c1\"># See http:\/\/elasticsearch-py.readthedocs.io\/en\/master\/connection.html?highlight=send_get_body_as#transport<\/span>\r\n<span class=\"c1\"># for details<\/span>\r\n<span class=\"c1\">#es_send_get_body_as: GET<\/span>\r\n\r\n<span class=\"c1\"># Option basic-auth username and password for elasticsearch<\/span>\r\n<span class=\"c1\">#es_username: someusername<\/span>\r\n<span class=\"c1\">#es_password: somepassword<\/span>\r\n\r\n<span class=\"c1\"># The index on es_host which is used for metadata storage<\/span>\r\n<span class=\"c1\"># This can be a unmapped index, but it is recommended that you run<\/span>\r\n<span class=\"c1\"># elastalert-create-index to set a mapping<\/span>\r\n<span class=\"na\">writeback_index<\/span><span class=\"pi\">:<\/span> <span class=\"s\">elastalert_status<\/span>\r\n\r\n<span class=\"c1\"># If an alert fails for some reason, ElastAlert will retry<\/span>\r\n<span class=\"c1\"># sending the alert until this time period has elapsed<\/span>\r\n<span class=\"na\">alert_time_limit<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">days<\/span><span class=\"pi\">:<\/span> <span class=\"m\">2<\/span>\r\n<\/code><\/pre>\n<p>\u5c06 es_host \u7684\u503c\u4ece\u300clocalhost\u300d\u66f4\u6539\u4e3a\u300celasticsearch\u300d\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"c1\"># The elasticsearch hostname for metadata writeback<\/span>\r\n<span class=\"c1\"># Note that every rule can have its own elasticsearch host<\/span>\r\n<span class=\"na\">es_host<\/span><span class=\"pi\">:<\/span> <span class=\"s\">elasticsearch<\/span>\r\n\r\n<span class=\"c1\"># The elasticsearch port<\/span>\r\n<span class=\"na\">es_port<\/span><span class=\"pi\">:<\/span> <span class=\"m\">9200<\/span>\r\n\r\n<span class=\"c1\"># This is the folder that contains the rule yaml files<\/span>\r\n<span class=\"c1\"># Any .yaml file will be loaded as a rule<\/span>\r\n<span class=\"na\">rules_folder<\/span><span class=\"pi\">:<\/span> <span class=\"s\">rules<\/span>\r\n\r\n<span class=\"c1\"># How often ElastAlert will query elasticsearch<\/span>\r\n<span class=\"c1\"># The unit can be anything from weeks to seconds<\/span>\r\n<span class=\"na\">run_every<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">seconds<\/span><span class=\"pi\">:<\/span> <span class=\"m\">5<\/span>\r\n\r\n<span class=\"c1\"># ElastAlert will buffer results from the most recent<\/span>\r\n<span class=\"c1\"># period of time, in case some log sources are not in real time<\/span>\r\n<span class=\"na\">buffer_time<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">minutes<\/span><span class=\"pi\">:<\/span> <span class=\"m\">1<\/span>\r\n\r\n<span class=\"c1\"># Optional URL prefix for elasticsearch<\/span>\r\n<span class=\"c1\">#es_url_prefix: elasticsearch<\/span>\r\n\r\n<span class=\"c1\"># Connect with TLS to elasticsearch<\/span>\r\n<span class=\"c1\">#use_ssl: True<\/span>\r\n\r\n<span class=\"c1\"># Verify TLS certificates<\/span>\r\n<span class=\"c1\">#verify_certs: True<\/span>\r\n\r\n<span class=\"c1\"># GET request with body is the default option for Elasticsearch.<\/span>\r\n<span class=\"c1\"># If it fails for some reason, you can pass 'GET', 'POST' or 'source'.<\/span>\r\n<span class=\"c1\"># See http:\/\/elasticsearch-py.readthedocs.io\/en\/master\/connection.html?highlight=send_get_body_as#transport<\/span>\r\n<span class=\"c1\"># for details<\/span>\r\n<span class=\"c1\">#es_send_get_body_as: GET<\/span>\r\n\r\n<span class=\"c1\"># Option basic-auth username and password for elasticsearch<\/span>\r\n<span class=\"c1\">#es_username: someusername<\/span>\r\n<span class=\"c1\">#es_password: somepassword<\/span>\r\n\r\n<span class=\"c1\"># The index on es_host which is used for metadata storage<\/span>\r\n<span class=\"c1\"># This can be a unmapped index, but it is recommended that you run<\/span>\r\n<span class=\"c1\"># elastalert-create-index to set a mapping<\/span>\r\n<span class=\"na\">writeback_index<\/span><span class=\"pi\">:<\/span> <span class=\"s\">elastalert_status<\/span>\r\n\r\n<span class=\"c1\"># If an alert fails for some reason, ElastAlert will retry<\/span>\r\n<span class=\"c1\"># sending the alert until this time period has elapsed<\/span>\r\n<span class=\"na\">alert_time_limit<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">days<\/span><span class=\"pi\">:<\/span> <span class=\"m\">2<\/span>\r\n<\/code><\/pre>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d41e037434c4406c975fd\/103-5.png\" alt=\"6.PNG\" \/><\/div>\n<h2>Praeco (\u62c9\u4e01\u8bed)<\/h2>\n<p>\u7ef4\u62a4\u4eba\u5458\uff1aJohn Susek\u3001Naoyuki Sano<br \/>\n\u8bb8\u53ef\u8bc1\uff1aGNU\u901a\u7528\u516c\u5171\u8bb8\u53ef\u8bc1v3.0<br \/>\n\u7248\u672c\u53f7\uff1a1.8.11\uff082021\/05\/27\uff09<\/p>\n<p>\u4f7f\u7528Helm\u5728Kubernetes\u4e0a\u5b89\u88c5Praeco\uff08ElastAlert GUI\uff09\uff08Beta\u7248\u672c\uff09<br \/>\n\u89e3\u51b3Praeco + ElastAlert2.0 + ES7.x\u914d\u7f6e\u7684\u95ee\u9898<br \/>\n\u4f7f\u7528Praeco\uff08ElastAlert GUI\uff09\u5bf9Elasticsearch\u65e5\u5fd7\u8fdb\u884c\u8b66\u62a5<br \/>\nPraeco\u3001ElastAlertServer\u3001Hive\u7b49\uff08\u82f1\u8bed\uff09<\/p>\n<p>\u30fbPraeco\u4f7f\u7528johnsusek\/elastalert-server \u8fd9\u4e2aBitSensor\u5f00\u53d1\u7684ElastAlert Server\u7684Fork\u3002<br \/>\n\u30fb\u901a\u8fc7\u4f7f\u7528Praeco\uff0c\u53ef\u4ee5\u5728\u56fe\u5f62\u754c\u9762\u4e0a\u64cd\u4f5cElastAlert\uff0c\u5e76\u4eceElasticsearch\u7684\u65e5\u5fd7\u4e2d\u8bbe\u7f6e\u8b66\u62a5\u901a\u77e5\u3002<br \/>\n\u30fb\u8b66\u62a5\u89c4\u5219\u8bbe\u7f6e<br \/>\n\u30fb\u8b66\u62a5\u5386\u53f2\u8bb0\u5f55<br \/>\n\u2192 \u57281.0.1\u7248\u672c\u4e2d\u672a\u663e\u793a\u4efb\u4f55\u5185\u5bb9\u3002\u5df2\u57281.1.0\u7248\u672c\u4e2d\u4fee\u590d(2020\/6\/17\u786e\u8ba4)<br \/>\n\u30fb\u67e5\u8be2\u5386\u53f2\u8bb0\u5f55<br \/>\n\u30fb\u7981\u7528\u4e00\u5b9a\u65f6\u95f4\u6bb5\u7684\u8b66\u62a5\u89c4\u5219<br \/>\n\u30fb\u652f\u6301Elasticsearch 7(0.4.2\uff5e)<br \/>\n\u30fb\u8b66\u62a5\u901a\u77e5\u65b9\u5f0f\u5305\u62ecSlack\u3001Email\u3001HTTP POST\u3001Telegram\u3001Jira\u3001MS Teams\u3001Mattermost\u3001Command\u3001Line Notify\u3001Gitter\u3001Zabbix\u3001SNS\u3001Twilio\u3001PagerTree\u3001Exotel\u3001GoogleChat\u3001Stomp\u3001VictorOps\u3001ServiceNow\u3001Chatwork\u3001Discord\u3001TheHive\u3001Alerta, Datadog\u3001AWS SES\u3001Rocket.Chat\u7684\u8bbe\u7f6e\u3002<br \/>\n\u30fb\u4e0d\u652f\u6301Percentage Match\u548cSpike Aggregation\u89c4\u5219\u7c7b\u578b\u3002<br \/>\n\u6dfb\u52a0&#8221;Percentage Match&#8221;\u89c4\u5219\u7c7b\u578b #82<br \/>\n\u6dfb\u52a0&#8221;Spike Aggregation&#8221;\u89c4\u5219\u7c7b\u578b #228<br \/>\n\u30fbElastAlert Server\u65e0\u6cd5\u8fde\u63a5Amazon Elasticsearch Service\u3002<\/p>\n<h4>Docker\u955c\u50cf<\/h4>\n<div>\n<div class=\"post-table\">Docker\u30a4\u30e1\u30fc\u30b8\u540d\u30bf\u30b0Praeco\u5099\u8003<a href=\"https:\/\/hub.docker.com\/r\/praecoapp\/praeco\" target=\"_blank\" rel=\"nofollow noopener\">praecoapp\/praeco<\/a>latest1.8.11<\/div>\n<\/div>\n<pre class=\"post-pre\"><code><span class=\"go\">mkdir Dockerfiles\r\ntouch Dockerfiles\/Dockerfile.elastalert\r\nmkdir -p es\/config\r\ntouch es\/config\/elasticsearch.yml\r\nmkdir -p es\/data\r\nchmod 777 es\/data\r\nmkdir -p kibana\/config\r\ntouch kibana\/config\/kibana.yml\r\nmkdir -p praeco\/bin\r\ntouch praeco\/bin\/elastalert-start.sh\r\ntouch praeco\/bin\/elastic_search_status.sh\r\nmkdir -p praeco\/config\r\nmkdir -p praeco\/nginx_config\r\nmkdir -p praeco\/public\r\nmkdir -p praeco\/public\/js\r\nmkdir -p praeco\/rule_templates\r\nchmod 777 praeco\/rule_templates\r\nmkdir -p praeco\/rules\r\nchmod 777 praeco\/rules\r\ncd praeco\/rules\r\nwget https:\/\/raw.githubusercontent.com\/johnsusek\/praeco\/master\/rules\/BaseRule.config\r\ncd ..\/\r\ncd praeco\/config\r\nwget https:\/\/raw.githubusercontent.com\/johnsusek\/praeco\/master\/config\/api.config.json\r\nwget https:\/\/raw.githubusercontent.com\/johnsusek\/praeco\/master\/config\/elastalert.yaml\r\ncd ..\/\r\ncd nginx_config\r\nwget https:\/\/raw.githubusercontent.com\/johnsusek\/praeco\/master\/nginx_config\/default.conf\r\nwget https:\/\/raw.githubusercontent.com\/johnsusek\/praeco\/master\/nginx_config\/nginx.conf\r\ncd ..\/\r\ncd public\r\nwget https:\/\/raw.githubusercontent.com\/johnsusek\/praeco\/master\/public\/praeco.config.json\r\ncd ..\/..\/\r\n\r\ndocker-compose up -d\r\n<\/span><\/code><\/pre>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d41e037434c4406c975fd\/111-0.png\" alt=\"praeco.PNG\" \/><\/div>\n<pre class=\"post-pre\"><code>\/home\/\u30e6\u30fc\u30b6\u30fc\u540d\/dkwork\/es\/\r\n|--docker-compose.yml\r\n|--Dockerfiles\r\n|  |--Dockerfile.elastalert\r\n|--es\r\n|  |--config\r\n|  |  |--elasticsearch.yml\r\n|  |--data\r\n|\r\n|--kibana\r\n|  |--config\r\n|  |  |--kibana.yml\r\n|\r\n|--praeco\r\n| |--bin\r\n| |  |--elastalert-start.sh\r\n| |  |--elastic_search_status.sh\r\n| |--config\r\n| |  |--api.config.json\r\n| |  |--elastalert.yaml\r\n| |--public\r\n| |  |--praeco.config.json\r\n| |--rule_templates\r\n| |--rules\r\n| |  |--BaseRule.config\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code>FROM johnsusek\/elastalert-server:latest\r\n\r\nUSER root\r\n\r\nRUN apk update &amp;&amp; \\\r\n    apk add bash curl &amp;&amp; \\\r\n    rm -rf \/var\/cache\/apk\/*\r\n\r\nADD praeco\/bin\/elastalert-start.sh \/usr\/local\/bin\/\r\nADD praeco\/bin\/elastic_search_status.sh \/usr\/local\/bin\/\r\n\r\nRUN chmod +x \/usr\/local\/bin\/elastalert-start.sh \r\nRUN chmod +x \/usr\/local\/bin\/elastic_search_status.sh\r\n\r\nUSER node\r\n\r\nENTRYPOINT [\"\/usr\/local\/bin\/elastalert-start.sh\"]\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"c\">#!\/bin\/bash<\/span>\r\n\r\n<span class=\"nb\">set<\/span> <span class=\"nt\">-e<\/span>\r\n\r\n<span class=\"k\">if<\/span> <span class=\"o\">[<\/span> <span class=\"nv\">$# <\/span><span class=\"nt\">-gt<\/span> 0 <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n  <\/span><span class=\"nv\">ES_URL<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"<\/span><span class=\"nv\">$1<\/span><span class=\"s2\">\"<\/span>\r\n<span class=\"k\">elif<\/span> <span class=\"o\">[[<\/span> <span class=\"nt\">-n<\/span> <span class=\"nv\">$ELASTICSEARCH_URL<\/span> <span class=\"o\">]]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n  <\/span><span class=\"nv\">ES_URL<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"<\/span><span class=\"nv\">$ELASTICSEARCH_URL<\/span><span class=\"s2\">\"<\/span>\r\n<span class=\"k\">elif<\/span> <span class=\"o\">[[<\/span> <span class=\"nt\">-n<\/span> <span class=\"nv\">$ES_HOST<\/span> <span class=\"o\">]]<\/span> <span class=\"o\">&amp;&amp;<\/span> <span class=\"o\">[[<\/span> <span class=\"nt\">-n<\/span> <span class=\"nv\">$ES_PORT<\/span> <span class=\"o\">]]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n  <\/span><span class=\"nv\">ES_URL<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"http:\/\/<\/span><span class=\"nv\">$ES_HOST<\/span><span class=\"s2\">:<\/span><span class=\"nv\">$ES_PORT<\/span><span class=\"s2\">\"<\/span>\r\n<span class=\"k\">else\r\n  <\/span><span class=\"nv\">ES_URL<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"http:\/\/elasticsearch:9200\"<\/span>\r\n<span class=\"k\">fi\r\n\r\nuntil<\/span> <span class=\"o\">[[<\/span> <span class=\"s2\">\"<\/span><span class=\"si\">$(<\/span>curl <span class=\"nt\">-fsSL<\/span> <span class=\"s2\">\"<\/span><span class=\"nv\">$ES_URL<\/span><span class=\"s2\">\/_cat\/health?h=status\"<\/span> | <span class=\"nb\">sed<\/span> <span class=\"nt\">-r<\/span> <span class=\"s1\">'s\/^[[:space:]]+|[[:space:]]+$\/\/g'<\/span><span class=\"si\">)<\/span><span class=\"s2\">\"<\/span> <span class=\"o\">=<\/span>~ ^<span class=\"o\">(<\/span>yellow|green<span class=\"o\">)<\/span><span class=\"nv\">$ <\/span><span class=\"o\">]]<\/span><span class=\"p\">;<\/span> <span class=\"k\">do<\/span>\r\n  <span class=\"c\"># printf '+' &gt;&amp;2<\/span>\r\n  <span class=\"nb\">sleep <\/span>1\r\n<span class=\"k\">done\r\n\r\n<\/span><span class=\"nb\">echo<\/span> <span class=\"s2\">\"Elasticsearch is up and healthy at \"<\/span><span class=\"nv\">$ES_URL<\/span><span class=\"s2\">\"\"<\/span> <span class=\"o\">&gt;<\/span>&amp;2\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"c\">#!\/bin\/bash<\/span>\r\n\r\n<span class=\"nb\">set<\/span> <span class=\"nt\">-e<\/span>\r\n\r\n<span class=\"nb\">echo<\/span> <span class=\"s2\">\"Giving Elasticsearch at <\/span><span class=\"nv\">$ELASTICSEARCH_URL<\/span><span class=\"s2\"> time to start...\"<\/span>\r\n\r\nelastic_search_status.sh\r\n\r\n<span class=\"nb\">echo<\/span> <span class=\"s2\">\"Starting ElastAlert!\"<\/span>\r\nnpm start\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"na\">cluster.name<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">docker-cluster\"<\/span>\r\n<span class=\"na\">network.host<\/span><span class=\"pi\">:<\/span> <span class=\"s\">0.0.0.0<\/span>\r\n<span class=\"na\">discovery.zen.minimum_master_nodes<\/span><span class=\"pi\">:<\/span> <span class=\"m\">1<\/span>\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"na\">server.name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">kibana<\/span>\r\n<span class=\"na\">server.host<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">0\"<\/span>\r\n<span class=\"na\">elasticsearch.hosts<\/span><span class=\"pi\">:<\/span> <span class=\"s\">http:\/\/elasticsearch:9200<\/span>\r\n<span class=\"na\">xpack.monitoring.ui.container.elasticsearch.enabled<\/span><span class=\"pi\">:<\/span> <span class=\"kc\">true<\/span>\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"na\">version<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">3.7\"<\/span>\r\n<span class=\"na\">services<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">elasticsearch<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">container_name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">elasticsearch<\/span>\r\n    <span class=\"na\">image<\/span><span class=\"pi\">:<\/span> <span class=\"s\">docker.elastic.co\/elasticsearch\/elasticsearch:7.7.0<\/span>\r\n    <span class=\"na\">ports<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">9200:9200<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">9300:9300<\/span>\r\n    <span class=\"na\">environment<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">ES_JAVA_OPTS=-Xms256m -Xmx512m<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">discovery.type=single-node<\/span>\r\n    <span class=\"na\">restart<\/span><span class=\"pi\">:<\/span> <span class=\"s\">always<\/span>\r\n    <span class=\"na\">volumes<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">.\/es\/data:\/usr\/share\/elasticsearch\/data<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">.\/es\/config\/elasticsearch.yml:\/usr\/share\/elasticsearch\/config\/elasticsearch.yml<\/span>\r\n    <span class=\"na\">healthcheck<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"na\">test<\/span><span class=\"pi\">:<\/span> <span class=\"pi\">[<\/span><span class=\"s2\">\"<\/span><span class=\"s\">CMD-SHELL\"<\/span><span class=\"pi\">,<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">curl<\/span> <span class=\"s\">-f<\/span> <span class=\"s\">http:\/\/localhost:9200<\/span> <span class=\"s\">||<\/span> <span class=\"s\">exit<\/span> <span class=\"s\">1\"<\/span><span class=\"pi\">]<\/span>\r\n        <span class=\"na\">interval<\/span><span class=\"pi\">:<\/span> <span class=\"s\">30s<\/span>\r\n        <span class=\"na\">timeout<\/span><span class=\"pi\">:<\/span> <span class=\"s\">15s<\/span>\r\n        <span class=\"na\">retries<\/span><span class=\"pi\">:<\/span> <span class=\"m\">3<\/span>\r\n        <span class=\"na\">start_period<\/span><span class=\"pi\">:<\/span> <span class=\"s\">180s<\/span>\r\n\r\n  <span class=\"na\">kibana<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">container_name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">kibana<\/span>\r\n    <span class=\"na\">image<\/span><span class=\"pi\">:<\/span> <span class=\"s\">docker.elastic.co\/kibana\/kibana:7.7.0<\/span>\r\n    <span class=\"na\">ports<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">5601:5601<\/span>\r\n    <span class=\"na\">depends_on<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">elasticsearch<\/span>\r\n    <span class=\"na\">restart<\/span><span class=\"pi\">:<\/span> <span class=\"s\">always<\/span>\r\n    <span class=\"na\">volumes<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">.\/kibana\/config\/kibana.yml:\/usr\/share\/kibana\/config\/kibana.yml<\/span>\r\n    <span class=\"na\">healthcheck<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"na\">test<\/span><span class=\"pi\">:<\/span> <span class=\"pi\">[<\/span><span class=\"s2\">\"<\/span><span class=\"s\">CMD-SHELL\"<\/span><span class=\"pi\">,<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">curl<\/span> <span class=\"s\">-f<\/span> <span class=\"s\">http:\/\/localhost:5601\/api\/status<\/span> <span class=\"s\">||<\/span> <span class=\"s\">exit<\/span> <span class=\"s\">1\"<\/span><span class=\"pi\">]<\/span>\r\n        <span class=\"na\">interval<\/span><span class=\"pi\">:<\/span> <span class=\"s\">30s<\/span>\r\n        <span class=\"na\">timeout<\/span><span class=\"pi\">:<\/span> <span class=\"s\">15s<\/span>\r\n        <span class=\"na\">retries<\/span><span class=\"pi\">:<\/span> <span class=\"m\">3<\/span>\r\n        <span class=\"na\">start_period<\/span><span class=\"pi\">:<\/span> <span class=\"s\">200s<\/span>\r\n\r\n  <span class=\"na\">elastalert<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">container_name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">elastalert<\/span>\r\n    <span class=\"na\">build<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">context<\/span><span class=\"pi\">:<\/span> <span class=\"s\">.<\/span>\r\n      <span class=\"na\">dockerfile<\/span><span class=\"pi\">:<\/span> <span class=\"s\">Dockerfiles\/Dockerfile.elastalert<\/span>\r\n    <span class=\"na\">image<\/span><span class=\"pi\">:<\/span> <span class=\"s\">elastalert-server:1.1.0<\/span>\r\n    <span class=\"na\">ports<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">3030:3030<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">3333:3333<\/span>\r\n    <span class=\"na\">depends_on<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">elasticsearch<\/span>\r\n    <span class=\"na\">restart<\/span><span class=\"pi\">:<\/span> <span class=\"s\">always<\/span>\r\n    <span class=\"na\">volumes<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">.\/praeco\/config\/elastalert.yaml:\/opt\/elastalert\/config.yaml<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">.\/praeco\/config\/api.config.json:\/opt\/elastalert-server\/config\/config.json<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">.\/praeco\/rules:\/opt\/elastalert\/rules<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">.\/praeco\/rule_templates:\/opt\/elastalert\/rule_templates<\/span>\r\n    <span class=\"na\">healthcheck<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"na\">test<\/span><span class=\"pi\">:<\/span> <span class=\"pi\">[<\/span><span class=\"s2\">\"<\/span><span class=\"s\">CMD-SHELL\"<\/span><span class=\"pi\">,<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">curl<\/span> <span class=\"s\">-f<\/span> <span class=\"s\">http:\/\/localhost:3030<\/span> <span class=\"s\">||<\/span> <span class=\"s\">exit<\/span> <span class=\"s\">1\"<\/span><span class=\"pi\">]<\/span>\r\n        <span class=\"na\">interval<\/span><span class=\"pi\">:<\/span> <span class=\"s\">30s<\/span>\r\n        <span class=\"na\">timeout<\/span><span class=\"pi\">:<\/span> <span class=\"s\">15s<\/span>\r\n        <span class=\"na\">retries<\/span><span class=\"pi\">:<\/span> <span class=\"m\">3<\/span>\r\n        <span class=\"na\">start_period<\/span><span class=\"pi\">:<\/span> <span class=\"s\">200s<\/span>\r\n\r\n  <span class=\"na\">praeco<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">container_name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">praeco<\/span>\r\n    <span class=\"na\">image<\/span><span class=\"pi\">:<\/span> <span class=\"s\">johnsusek\/praeco:latest<\/span>\r\n    <span class=\"na\">ports<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">8080:8080<\/span>\r\n    <span class=\"na\">depends_on<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">elastalert<\/span>\r\n    <span class=\"na\">restart<\/span><span class=\"pi\">:<\/span> <span class=\"s\">always<\/span>\r\n    <span class=\"na\">volumes<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">.\/praeco\/public\/praeco.config.json:\/var\/www\/html\/praeco.config.json<\/span>\r\n    <span class=\"na\">healthcheck<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"na\">test<\/span><span class=\"pi\">:<\/span> <span class=\"pi\">[<\/span><span class=\"s2\">\"<\/span><span class=\"s\">CMD-SHELL\"<\/span><span class=\"pi\">,<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">curl<\/span> <span class=\"s\">-f<\/span> <span class=\"s\">http:\/\/localhost:8080<\/span> <span class=\"s\">||<\/span> <span class=\"s\">exit<\/span> <span class=\"s\">1\"<\/span><span class=\"pi\">]<\/span>\r\n        <span class=\"na\">interval<\/span><span class=\"pi\">:<\/span> <span class=\"s\">30s<\/span>\r\n        <span class=\"na\">timeout<\/span><span class=\"pi\">:<\/span> <span class=\"s\">15s<\/span>\r\n        <span class=\"na\">retries<\/span><span class=\"pi\">:<\/span> <span class=\"m\">3<\/span>\r\n        <span class=\"na\">start_period<\/span><span class=\"pi\">:<\/span> <span class=\"s\">200s<\/span>\r\n<\/code><\/pre>\n<p>\u4ee5\u4e0b\u6587\u4ef6\u4f7f\u7528\u7684\u662fPraeco\u7f51\u7ad9\u4e0a\u7684\u5185\u5bb9\uff1a<br \/>\nhttps:\/\/github.com\/johnsusek\/praeco<br \/>\n\u30fbpraeco\/config\/api.config.json<br \/>\n\u30fbpraeco\/config\/elastalert.yaml<br \/>\n\u30fbpraeco\/public\/praeco.config.json<br \/>\n\u30fbpraeco\/rules\/BaseRule.config<\/p>\n<h2>\u5f00\u653e\u641c\u7d22<\/h2>\n<p>2.4.1 (2022\/12\/03)<br \/>\n\u5236\u9020\u5546\uff1aAWS<\/p>\n<p>\u4e9a\u9a6c\u900a\u5c06Elasticsearch\u7684Fork\u6539\u540d\u4e3aOpenSearch<br \/>\n\u4e9a\u9a6c\u900a\u7f51\u670d\u52a1(AWS)\u5ba3\u5e03\u4e86\u901a\u8fc7Elasticsearch\u548cKibana\u7684Fork\u63a8\u51fa\u7684&#8221;OpenSearch&#8221;\u9879\u76ee\u3002\u4e0eElastic\u4e4b\u95f4\u7684\u5206\u6b67\u4ecd\u7136\u5b58\u5728\u3002<br \/>\nElastic\u7684\u5ba2\u6237\u7aef\u5e93\u4e0d\u518d\u8fde\u63a5\u5230AWS\u7684OpenSearch\u3002AWS\u4e0d\u5f97\u4e0d\u5ba3\u5e03\u4e86\u5ba2\u6237\u7aef\u5e93\u7684Fork\u3002<\/p>\n<h2>\u5f00\u653e\u5206\u53d1 Elasticsearch<\/h2>\n<blockquote><p>\u5f00\u653e\u5f0f Elasticsearch \u4e3b\u9898\u7684\u5f00\u53d1\u5df2\u7ecf\u8fc1\u79fb\u81f3 OpenSearch\u3002ODFE \u63d2\u4ef6\u4ecd\u7136\u53ef\u4ee5\u4e0e Elasticsearch OSS \u7684\u65e7\u7248\u7ee7\u7eed\u4f7f\u7528\uff0c\u4f46\u6211\u4eec\u5efa\u8bae\u5347\u7ea7\u5230 OpenSearch\uff0c\u4ee5\u4fbf\u4eab\u53d7\u6700\u65b0\u7684\u529f\u80fd\u4e0e\u6539\u8fdb\u3002<\/p><\/blockquote>\n<p>Elasticsearch\u5f00\u53d1\u7528\u7684OpenDistro\u5df2\u7ecf\u8fc1\u79fb\u5230\u4e86OpenSearch\u3002ODFE\u63d2\u4ef6\u5c06\u7ee7\u7eed\u5728ElasticsearchOSS\u7684\u65e7\u7248\u672c\u4e2d\u8fd0\u884c\uff0c\u4f46\u5efa\u8bae\u60a8\u5347\u7ea7\u5230OpenSearch\u4ee5\u4f7f\u7528\u6700\u65b0\u7684\u529f\u80fd\u548c\u6539\u8fdb\u70b9\u3002<br \/>\nhttps:\/\/opendistro.github.io\/for-elasticsearch-docs\/<\/p>\n<p>\u5f00\u53d1\u5546\uff1aAWS<br \/>\n\u8bb8\u53ef\u8bc1\uff1aApache License 2.0<br \/>\n&#8220;Elasticsearch&#8221; \u7684\u4e13\u6709\u53d1\u884c\u7248<br \/>\n1.13.2\uff082021\u5e7404\u670807\u65e5\u3002Elastcsearch \u548c Kibana \u7684\u7248\u672c\u4e3a7.10.2\uff09<br \/>\namazon\/opendistro-for-elasticsearch<br \/>\namazon\/opendistro-for-elasticsearch-kibana<\/p>\n<p>\u5c1d\u8bd5\u79fb\u52a8\u753b\u9762\u540e\uff0c\u6211\u6ce8\u610f\u5230\u4e86\u4e00\u4e9b\u95ee\u9898(\u7248\u672c1.3.0)\u3002<\/p>\n<p>\u6709\u4e00\u4e2a\u767b\u5f55\u9875\u9762\u3002<br \/>\n\u521d\u59cb\u7684\u7528\u6237\u540d\/\u5bc6\u7801\u662fadmin\/admin\u3002<\/p>\n<p>\u5728\u5f53\u524d\u7248\u672c\u4e2d\uff0c\u65e0\u6cd5\u50cfX-Pack\u7684\u7d22\u5f15\u7ba1\u7406\u90a3\u6837\u5728\u754c\u9762\u4e0a\u5220\u9664\u7d22\u5f15\u5417\uff1f<\/p>\n<p>\u7c7b\u4f3c\u4e8eX-Pack\u7684Index Lifecycle Management\uff08ILM\uff09\u529f\u80fd\uff0c\u4f3c\u4e4e\u53ef\u4ee5\u901a\u8fc7\u5c4f\u5e55\u7f16\u8f91\u8bbe\u7f6eyaml\u7684\u529f\u80fd\u3002<\/p>\n<p>\u53ef\u4ee5\u5728\u5c4f\u5e55\u4e0a\u8bbe\u7f6e\u8b66\u62a5<br \/>\n\u5c1d\u8bd5\u4f7f\u7528Amazon Elasticsearch Service\u7684Alerting\u529f\u80fd\u76d1\u89c6AWS ConsoleLogin<\/p>\n<p>\u30fb\u76ee\u524d\u8fd8\u672a\u5b9e\u65bdCSV\/PDF\u6587\u4ef6\u8f93\u51fa\u529f\u80fd\uff0cPDF\u751f\u6210\u548c\u62a5\u544a #16\u3002<\/p>\n<p>\u4ee5\u4e0b\u5185\u5bb9\u5c1a\u672a\u786e\u8ba4\u3002<\/p>\n<p>\u5728\u4e2d\u56fd\u5883\u5185\u662f\u5426\u53ef\u4ee5\u4f7f\u7528Elastic\u793e\u7684Kibana 7.4.2\u7248\u672c\u5bfc\u5165\u521b\u5efa\u7684\u4eea\u8868\u677f\uff1f\u800c\u5982\u679c\u662f\u4f7f\u75287.4.2\u4ee5\u4e0a\u7684\u7248\u672c\u5462\uff0c\u4f1a\u600e\u6837\u5462\uff1f<\/p>\n<p>\u30fb\u5728Fluentd\u7684Elastcsearch\u63d2\u4ef6\u8bbe\u7f6e\u4e2d\uff0c\u5e94\u8be5\u65e0\u6cd5\u4f7f\u7528Index Lifecycle Management\uff08ILM\uff09\u7684\u914d\u7f6e\uff0c\u6240\u4ee5\u5982\u679c\u6709\u914d\u7f6e\u7684\u8bdd\uff0c\u9700\u8981\u5c06\u5176\u6ce8\u91ca\u5e76\u8fdb\u884c\u64cd\u4f5c\u786e\u8ba4\u3002<\/p>\n<p>\u53ef\u80fd\u9700\u8981\u5378\u8f7dFluentd\u7684X-Pack\u63d2\u4ef6\u4ee5\u8fdb\u884c\u64cd\u4f5c\u786e\u8ba4\u3002<\/p>\n<p>\u7531\u4e8e\u5bf9\u4e8eFluentd\u3001Metricbeat\u3001Filebeat\u3001Heartbeat\u548cLogstash\u8fd9\u4e9b\u5de5\u5177\u7684\u4fe1\u606f\u8fd8\u5f88\u5c11\uff0c\u56e0\u6b64\u9700\u8981\u6839\u636e\u73b0\u6709\u4fe1\u606f\u6765\u8c03\u67e5\u548c\u8003\u8651\u4f7f\u7528\u7684\u914d\u7f6e\u3002<\/p>\n<p>\u5b89\u5168<br \/>\nhttps:\/\/opendistro.github.io\/for-elasticsearch-docs\/docs\/security-configuration\/<br \/>\nhttps:\/\/opendistro.github.io\/for-elasticsearch-docs\/docs\/security-access-control\/<br \/>\nhttps:\/\/opendistro.github.io\/for-elasticsearch-docs\/docs\/security-audit-logs\/<\/p>\n<p>\u5b89\u5168\u63aa\u65bd<br \/>\nhttps:\/\/opendistro.github.io\/for-elasticsearch-docs\/docs\/security-configuration\/<br \/>\nhttps:\/\/opendistro.github.io\/for-elasticsearch-docs\/docs\/security-access-control\/<br \/>\nhttps:\/\/opendistro.github.io\/for-elasticsearch-docs\/docs\/security-audit-logs\/<\/p>\n<p>\u63d0\u9192\u529f\u80fd<br \/>\nhttps:\/\/opendistro.github.io\/for-elasticsearch-docs\/docs\/alerting\/<\/p>\n<p>SQL\uff08\u7ed3\u6784\u5316\u67e5\u8be2\u8bed\u8a00\uff09<\/p>\n<p>\u6307\u6807\u72b6\u6001\u7ba1\u7406\uff08ISM\uff09<br \/>\n\u7c7b\u4f3c\u4e8eX-Pack\u7684\u7d22\u5f15\u751f\u547d\u5468\u671f\u7ba1\u7406\uff08ILM\uff09\u529f\u80fd<br \/>\nhttps:\/\/opendistro.github.io\/for-elasticsearch-docs\/docs\/ism\/<\/p>\n<p>KNN\u7b97\u6cd5<br \/>\nhttps:\/\/opendistro.github.io\/for-elasticsearch-docs\/docs\/knn\/<\/p>\n<p>\u5f02\u5e38\u68c0\u6d4b\uff08Alpha\u7248\u672c\uff09<br \/>\nhttps:\/\/opendistro.github.io\/for-elasticsearch-docs\/docs\/ad\/<\/p>\n<p>\u6027\u80fd\u5206\u6790\u5668<br \/>\nhttps:\/\/opendistro.github.io\/for-elasticsearch-docs\/docs\/pa\/<\/p>\n<p>\u6839\u672c\u539f\u56e0\u5206\u6790\uff08Alpha\u7248\uff09<\/p>\n<p>Fluentd<br \/>\nFluentd\u7684\u652f\u6301<br \/>\n\u81ea\u7b7e\u540d\u8bc1\u4e66\u9a8c\u8bc1\u5931\u8d25\uff08Fluentd + Open Distro for Elasticsearch\uff09\uff03597<\/p>\n<p>\u80cc\u666f<br \/>\n\u5c1d\u8bd5\u4f7f\u7528Logstash\u548cFilebeat\u8fde\u63a5\u7684Open Distro for Elasticsearch\u95ee\u9898<br \/>\n\u4e0eBeats\u8fdb\u884c\u96c6\u6210<br \/>\n\u65e0\u6cd5\u4f7f\u7528LogStash\u7d22\u5f15Filebeat\u65e5\u5fd7 #136<br \/>\nFilebeat 6.5.4\u8f93\u51fa\u5230Elasticsearch #21<br \/>\nMetricbeat\u7528\u6237\u6743\u9650<br \/>\n\u914d\u7f6e\u4f7f\u7528opendistro\u7684OSS Beats\uff08\u6587\u4ef6\/\u5ea6\u91cf\uff09<br \/>\n\u4f7f\u7528metricbeat\u53c2\u6570\u8fdb\u884c\u8b66\u62a5 #13<br \/>\nLogstash\u96c6\u6210<\/p>\n<p>\u65b0\u767b\u5834-Open Distro for Elasticsearch<br \/>\n\u5c0dAWS\u7684Open Distro for Elasticsearch\u63d0\u51fa\u7570\u8b70\u7684\u4f9b\u61c9\u5546\u5011<br \/>\nAWS\u4ee5Apache\u8a31\u53ef\u8b49\u516c\u958b\u4e86Elasticsearch\u7684\u65b0\u767c\u884c\u7248<br \/>\n\u5617\u8a66\u5275\u5efaOpen Distro for Elasticsearch\uff01<br \/>\nOpen Distro for Elasticsearch\u555f\u52d5\u6307\u5357<br \/>\n[\u66f4\u65b0] Amazon Elasticsearch Service\u73fe\u5728\u652f\u6301\u8b66\u5831\u529f\u80fd<\/p>\n<h2>Grafana &#8211; \u56fe\u8868\u5c55\u793a\u5e94\u7528<\/h2>\n<p>\u9605\u8bfb\u65b9\u5f0f\uff1aGrafana<br \/>\n\u5f00\u53d1\u8005\uff1aGrafana Labs<br \/>\n\u8bb8\u53ef\u8bc1\uff1aApache License 2.0<br \/>\n9.3.2\uff082022-12-16\uff09<\/p>\n<p>\u4ece5.2.0\u5f00\u59cb\uff0c\u53ef\u4ee5\u5bf9Elasticsearch\u5185\u7684\u6570\u636e\u8fdb\u884c\u8b66\u62a5\u901a\u77e5\u3002<\/p>\n<p>\u3010\u8b66\u62a5\u3011<br \/>\n(https:\/\/grafana.com\/docs\/grafana\/latest\/alerting\/)<br \/>\n\u8b66\u62a5\u901a\u77e5<br \/>\nDingDing<br \/>\nDiscord<br \/>\n\u7535\u5b50\u90ae\u4ef6<br \/>\nGoogle Hangouts Chat<br \/>\nHipchat<br \/>\nKafka<br \/>\nLine<br \/>\nMicrosoft Teams<br \/>\nOpsGenie<br \/>\nPagerduty<br \/>\nPrometheus Alertmanager<br \/>\nPushover<br \/>\nSensu<br \/>\nSlack<br \/>\nSquadcast<br \/>\nTelegram<br \/>\nThreema<br \/>\nVictorOps<br \/>\nWebhook<br \/>\n\u521b\u5efa\u80fd\u591f\u4ee5SNMP Trap\u5f62\u5f0f\u53d1\u9001\u901a\u77e5\u7684\u8b66\u62a5<\/p>\n<blockquote><p>\u73b0\u5728\u4e0d\u652f\u6301\u8fd9\u4e2a<\/p><\/blockquote>\n<p>\u5728Grafana\u4e2d\u8bbe\u7f6e\u8b66\u62a5\u901a\u77e5<br \/>\nGrafana\u90ae\u4ef6\u901a\u77e5\u8bbe\u7f6e<br \/>\n\u5728Grafana\u90ae\u4ef6\u8bbe\u7f6e\u4e2d\u9047\u5230\u7684\u95ee\u9898<br \/>\n\u901a\u8fc7Grafana\u53d1\u9001\u7535\u5b50\u90ae\u4ef6\u901a\u77e5<\/p>\n<p>\u901a\u8fc7BLE\u83b7\u53d6\u7684\u6570\u636e\u8fdb\u884c\u53ef\u89c6\u5316\uff08\u4f7f\u7528Grafana\uff09\u548c\u8b66\u62a5\u901a\u77e5\uff08\u4f7f\u7528Slack\uff09\u7684\u5b9e\u65bd\u3002<br \/>\n\u5728Grafana\u4e0a\u6784\u5efa\u4e86\u5c06\u670d\u52a1\u5668\u6307\u6807\u5b58\u50a8\u5728Elasticsearch\u4e2d\u8fdb\u884c\u53ef\u89c6\u5316\u548c\u901a\u8fc7Slack\u901a\u77e5\u7684\u73af\u5883\uff08\u7531Nifcloud\u63d0\u4f9b\uff09\u3002<br \/>\n\u4f7f\u7528Prometheus+Grafana\u8fdb\u884c\u6027\u80fd\u76d1\u63a7\u3002<\/p>\n<p>\u4f7f\u7528Grafana5.2.0+\u6765\u6267\u884c\u5bf9Elasticsearch\u4e2d\u7684\u6570\u636e\u7684\u8b66\u62a5\uff0c\u5e76\u901a\u8fc7Discord\u8fdb\u884c\u901a\u77e5\u3002<\/p>\n<p>\u4f7f\u7528Grafana\u5728Teams\u4e0a\u53d1\u9001\u8b66\u62a5\u975e\u5e38\u5bb9\u6613\u3002<\/p>\n<p>\u4f7f\u7528Webhook\u5c06Prometheus2\u548cGrafana6\u4e0e\u7cfb\u7edf\u76d1\u63a7\u7ed3\u5408\u8d77\u6765\uff0c\u5e76\u5229\u7528Grafana\u7684\u8b66\u62a5\u529f\u80fd\u3002<\/p>\n<h2>\u5f39\u6027\u8b66\u62a5\u7528\u6237\u754c\u9762<\/h2>\n<p>\u8bb8\u53ef\u8bc1\u4e3aApache License 2.0\uff0c\u7ef4\u62a4\u5df2\u7ec8\u6b62\u3002GitHub\u7684\u6700\u540e\u66f4\u65b0\u65e5\u671f\u4e3a2018\/02\/12\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>X-Pack\u7684\u89c2\u5bdf\u8005\u8b66\u62a5 \u5f00\u53d1\u8005\uff1aElastic \u6536\u8d39\u7684 \u8ba9\u6211\u4eec\u5f00\u59cb\u4f7f\u7528 Watcher \u5c1d\u8bd5\u4f7f\u7528Elasti [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-40650","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v21.5 (Yoast SEO v21.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u8c03\u67e5\u57fa\u4e8eElasticsearch\u6570\u636e\u8fdb\u884c\u8b66\u62a5\u901a\u77e5\u7684\u65b9\u6cd5 - Blog - Silicon Cloud<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.silicloud.com\/zh\/blog\/\u8c03\u67e5\u57fa\u4e8eelasticsearch\u6570\u636e\u8fdb\u884c\u8b66\u62a5\u901a\u77e5\u7684\u65b9\u6cd5\u3002\/\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u8c03\u67e5\u57fa\u4e8eElasticsearch\u6570\u636e\u8fdb\u884c\u8b66\u62a5\u901a\u77e5\u7684\u65b9\u6cd5\" \/>\n<meta property=\"og:description\" content=\"X-Pack\u7684\u89c2\u5bdf\u8005\u8b66\u62a5 \u5f00\u53d1\u8005\uff1aElastic \u6536\u8d39\u7684 \u8ba9\u6211\u4eec\u5f00\u59cb\u4f7f\u7528 Watcher \u5c1d\u8bd5\u4f7f\u7528Elasti [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.silicloud.com\/zh\/blog\/\u8c03\u67e5\u57fa\u4e8eelasticsearch\u6570\u636e\u8fdb\u884c\u8b66\u62a5\u901a\u77e5\u7684\u65b9\u6cd5\u3002\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog - Silicon Cloud\" \/>\n<meta property=\"article:published_time\" content=\"2023-08-11T22:56:12+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-04-30T09:19:03+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d41e037434c4406c975fd\/103-5.png\" \/>\n<meta name=\"author\" content=\"\u97f5, \u79d1\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u97f5, \u79d1\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"18 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e8%b0%83%e6%9f%a5%e5%9f%ba%e4%ba%8eelasticsearch%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e8%ad%a6%e6%8a%a5%e9%80%9a%e7%9f%a5%e7%9a%84%e6%96%b9%e6%b3%95%e3%80%82\/\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e8%b0%83%e6%9f%a5%e5%9f%ba%e4%ba%8eelasticsearch%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e8%ad%a6%e6%8a%a5%e9%80%9a%e7%9f%a5%e7%9a%84%e6%96%b9%e6%b3%95%e3%80%82\/\",\"name\":\"\u8c03\u67e5\u57fa\u4e8eElasticsearch\u6570\u636e\u8fdb\u884c\u8b66\u62a5\u901a\u77e5\u7684\u65b9\u6cd5 - Blog - Silicon Cloud\",\"isPartOf\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\"},\"datePublished\":\"2023-08-11T22:56:12+00:00\",\"dateModified\":\"2024-04-30T09:19:03+00:00\",\"author\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/6530331a63adef3b3443a1fab53a0e6e\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e8%b0%83%e6%9f%a5%e5%9f%ba%e4%ba%8eelasticsearch%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e8%ad%a6%e6%8a%a5%e9%80%9a%e7%9f%a5%e7%9a%84%e6%96%b9%e6%b3%95%e3%80%82\/#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.silicloud.com\/zh\/blog\/%e8%b0%83%e6%9f%a5%e5%9f%ba%e4%ba%8eelasticsearch%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e8%ad%a6%e6%8a%a5%e9%80%9a%e7%9f%a5%e7%9a%84%e6%96%b9%e6%b3%95%e3%80%82\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e8%b0%83%e6%9f%a5%e5%9f%ba%e4%ba%8eelasticsearch%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e8%ad%a6%e6%8a%a5%e9%80%9a%e7%9f%a5%e7%9a%84%e6%96%b9%e6%b3%95%e3%80%82\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.silicloud.com\/zh\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u8c03\u67e5\u57fa\u4e8eElasticsearch\u6570\u636e\u8fdb\u884c\u8b66\u62a5\u901a\u77e5\u7684\u65b9\u6cd5\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/\",\"name\":\"Blog - Silicon Cloud\",\"description\":\"\",\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/6530331a63adef3b3443a1fab53a0e6e\",\"name\":\"\u97f5, \u79d1\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/429ccb39b3fff5188bc17986222cfb0936cbadb8cc933cff04ab5ca01bd30a08?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/429ccb39b3fff5188bc17986222cfb0936cbadb8cc933cff04ab5ca01bd30a08?s=96&d=mm&r=g\",\"caption\":\"\u97f5, \u79d1\"},\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/author\/yunke\/\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e8%b0%83%e6%9f%a5%e5%9f%ba%e4%ba%8eelasticsearch%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e8%ad%a6%e6%8a%a5%e9%80%9a%e7%9f%a5%e7%9a%84%e6%96%b9%e6%b3%95%e3%80%82\/#local-main-organization-logo\",\"url\":\"\",\"contentUrl\":\"\",\"caption\":\"Blog - Silicon Cloud\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u8c03\u67e5\u57fa\u4e8eElasticsearch\u6570\u636e\u8fdb\u884c\u8b66\u62a5\u901a\u77e5\u7684\u65b9\u6cd5 - Blog - Silicon Cloud","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.silicloud.com\/zh\/blog\/\u8c03\u67e5\u57fa\u4e8eelasticsearch\u6570\u636e\u8fdb\u884c\u8b66\u62a5\u901a\u77e5\u7684\u65b9\u6cd5\u3002\/","og_locale":"zh_CN","og_type":"article","og_title":"\u8c03\u67e5\u57fa\u4e8eElasticsearch\u6570\u636e\u8fdb\u884c\u8b66\u62a5\u901a\u77e5\u7684\u65b9\u6cd5","og_description":"X-Pack\u7684\u89c2\u5bdf\u8005\u8b66\u62a5 \u5f00\u53d1\u8005\uff1aElastic \u6536\u8d39\u7684 \u8ba9\u6211\u4eec\u5f00\u59cb\u4f7f\u7528 Watcher \u5c1d\u8bd5\u4f7f\u7528Elasti [&hellip;]","og_url":"https:\/\/www.silicloud.com\/zh\/blog\/\u8c03\u67e5\u57fa\u4e8eelasticsearch\u6570\u636e\u8fdb\u884c\u8b66\u62a5\u901a\u77e5\u7684\u65b9\u6cd5\u3002\/","og_site_name":"Blog - Silicon Cloud","article_published_time":"2023-08-11T22:56:12+00:00","article_modified_time":"2024-04-30T09:19:03+00:00","og_image":[{"url":"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d41e037434c4406c975fd\/103-5.png"}],"author":"\u97f5, \u79d1","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"\u97f5, \u79d1","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"18 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e8%b0%83%e6%9f%a5%e5%9f%ba%e4%ba%8eelasticsearch%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e8%ad%a6%e6%8a%a5%e9%80%9a%e7%9f%a5%e7%9a%84%e6%96%b9%e6%b3%95%e3%80%82\/","url":"https:\/\/www.silicloud.com\/zh\/blog\/%e8%b0%83%e6%9f%a5%e5%9f%ba%e4%ba%8eelasticsearch%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e8%ad%a6%e6%8a%a5%e9%80%9a%e7%9f%a5%e7%9a%84%e6%96%b9%e6%b3%95%e3%80%82\/","name":"\u8c03\u67e5\u57fa\u4e8eElasticsearch\u6570\u636e\u8fdb\u884c\u8b66\u62a5\u901a\u77e5\u7684\u65b9\u6cd5 - Blog - Silicon Cloud","isPartOf":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website"},"datePublished":"2023-08-11T22:56:12+00:00","dateModified":"2024-04-30T09:19:03+00:00","author":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/6530331a63adef3b3443a1fab53a0e6e"},"breadcrumb":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e8%b0%83%e6%9f%a5%e5%9f%ba%e4%ba%8eelasticsearch%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e8%ad%a6%e6%8a%a5%e9%80%9a%e7%9f%a5%e7%9a%84%e6%96%b9%e6%b3%95%e3%80%82\/#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.silicloud.com\/zh\/blog\/%e8%b0%83%e6%9f%a5%e5%9f%ba%e4%ba%8eelasticsearch%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e8%ad%a6%e6%8a%a5%e9%80%9a%e7%9f%a5%e7%9a%84%e6%96%b9%e6%b3%95%e3%80%82\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e8%b0%83%e6%9f%a5%e5%9f%ba%e4%ba%8eelasticsearch%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e8%ad%a6%e6%8a%a5%e9%80%9a%e7%9f%a5%e7%9a%84%e6%96%b9%e6%b3%95%e3%80%82\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.silicloud.com\/zh\/blog\/"},{"@type":"ListItem","position":2,"name":"\u8c03\u67e5\u57fa\u4e8eElasticsearch\u6570\u636e\u8fdb\u884c\u8b66\u62a5\u901a\u77e5\u7684\u65b9\u6cd5"}]},{"@type":"WebSite","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website","url":"https:\/\/www.silicloud.com\/zh\/blog\/","name":"Blog - Silicon Cloud","description":"","inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/6530331a63adef3b3443a1fab53a0e6e","name":"\u97f5, \u79d1","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/429ccb39b3fff5188bc17986222cfb0936cbadb8cc933cff04ab5ca01bd30a08?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/429ccb39b3fff5188bc17986222cfb0936cbadb8cc933cff04ab5ca01bd30a08?s=96&d=mm&r=g","caption":"\u97f5, \u79d1"},"url":"https:\/\/www.silicloud.com\/zh\/blog\/author\/yunke\/"},{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e8%b0%83%e6%9f%a5%e5%9f%ba%e4%ba%8eelasticsearch%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e8%ad%a6%e6%8a%a5%e9%80%9a%e7%9f%a5%e7%9a%84%e6%96%b9%e6%b3%95%e3%80%82\/#local-main-organization-logo","url":"","contentUrl":"","caption":"Blog - Silicon Cloud"}]}},"_links":{"self":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/40650","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/comments?post=40650"}],"version-history":[{"count":2,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/40650\/revisions"}],"predecessor-version":[{"id":93236,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/40650\/revisions\/93236"}],"wp:attachment":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/media?parent=40650"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/categories?post=40650"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/tags?post=40650"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}