如何编写Elasticsearch查询实现MetricBeat无数据5分钟的停止告警?
MetricBeat离线服务器告警的Elasticsearch Watcher配置
我们通过MetricBeat监控多台服务器,需要实现当任意服务器上的MetricBeat停止运行时触发告警,判定规则为:若某台服务器过去5分钟内未上报任何数据,则判定该服务器上的MetricBeat已停止运行。
以下是实现该需求的完整Elasticsearch Watcher配置:
PUT _watcher/watch/eba1f994-1306-4846-b586-5a2c6135b4bc { "trigger": { "schedule": { "interval": "30m" } }, "input": { "search": { "request": { "search_type": "query_then_fetch", "indices": [ "metricbeat-*" ], "rest_total_hits_as_int": true, "body": { "size": 0, "query": { "bool": { "filter": [ { "range": { "@timestamp": { "gte": "now-5m", "lte": "now" } } } ] } }, "aggs": { "servers": { "terms": { "field": "tags", "size": 1000, "min_doc_count": 0 } } } } } } }, "condition": { "array_compare": { "ctx.payload.aggregations.servers.buckets": { "path": "doc_count", "eq": { "value": 0, "quantifier": "some" } } } }, "actions": { "my-logging-action": { "logging": { "level": "info", "text": "以下服务器未发送数据: {{#ctx.payload.aggregations.servers.buckets}} {{key}} (数据量:{{doc_count}}),{{/ctx.payload.aggregations.servers.buckets}}" } } } }
关键配置说明
- 触发周期:每30分钟执行一次检查,可根据实际需求调整
interval参数 - 索引范围:匹配所有以
metricbeat-开头的索引,确保覆盖所有MetricBeat上报的数据 - 数据过滤:仅查询最近5分钟内的上报数据,对应
@timestamp的range过滤 - 聚合统计:通过
tags字段(需确保每个服务器的MetricBeat配置了唯一标识的tags值)分组,min_doc_count: 0保证即使无数据的服务器也会被统计出来 - 告警条件:当存在至少一个服务器的
doc_count为0时,触发告警 - 告警动作:示例中使用日志记录告警信息,实际场景可替换为邮件、Webhook等通知方式,将告警推送到指定渠道
内容的提问来源于stack exchange,提问作者aniketpant
相关产品推荐
相关产品推荐

