https://github.com/jertel/elastalert2
https://github.com/gpYang/elastalert-feishu-plugin
#!/bin/bash
docker stop elastalert
docker rm elastalert
docker run -d --name elastalert --restart=always \
-v $(pwd)/elastalert/elastalert.yaml:/opt/elastalert/config.yaml \
-v $(pwd)/elastalert/smtp_auth.yaml:/opt/elastalert/smtp_auth.yaml \
-v $(pwd)/elastalert/rules:/opt/elastalert/rules \
tangwan/elastalert-feishu:1.0 --verbose
rules_folder: /opt/elastalert/rules
run_every:
seconds: 20
buffer_time:
minutes: 10
es_host: 172.16.xxx.xxx
es_port: 9200
es_username: elastic
es_password: A123456
writeback_index: elastalert_status
alert_time_limit:
days: 1
user: [email protected]
password: ABC123321
name: "app-name"
type: "frequency"
index: "app-name-*"
is_enabled: true
num_events: 1
realert:
minutes: 5
exponential_realert:
hours: 1
terms_size: 50
timeframe:
minutes: 1
timestamp_field: "@timestamp"
timestamp_type: "iso"
use_strftime_index: false
filter:
- bool:
filter:
- match_all: {}
alert:
- "elastalert_modules.feishu_alert.FeishuAlert"
- "email"
# 邮箱服务配置,发送错误提醒到邮箱
smtp_host: smtp.exmail.qq.com
smtp_port: 465
smtp_ssl: true
smtp_auth_file: /opt/elastalert/smtp_auth.yaml
email_reply_to: [email protected]
from_addr: [email protected]
email:
- "[email protected]"
# 飞书机器人
feishualert_url: "https://open.feishu.cn/open-apis/bot/v2/hook/"
feishualert_botid: "xxxxxxxxxxxxxxxxxx"
feishualert_title: "app-name"
feishualert_skip:
start: "01:00:00"
end: "09:00:00"
# 告警内容,使用{}可匹配matches,如匹配到的es数据为{"host":"aa.com","ip":"127.0.0.1"}
feishualert_body:
"
告警应用: {feishualert_title}\n
告警环境: prod\n
错误数量: {num_hits}\n
触发时间: {feishualert_time}\n
错误信息: {message}
"
Content type
Image
Digest
sha256:51f200077…
Size
109.7 MB
Last updated
over 3 years ago
docker pull tangwan/elastalert-feishu:1.0