You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为匹配指定模式的Elasticsearch索引总大小设置告警规则

索引总大小超过阈值告警的实现方案

方案一:利用Metricbeat采集指标+Kibana告警规则

1. 配置Metricbeat采集索引统计数据

修改Metricbeat的配置文件,启用Elasticsearch模块并指定要监控的索引模式:

- module: elasticsearch
  metricsets: ["index"]
  hosts: ["http://你的ES地址:9200"]
  username: "你的用户名"
  password: "你的密码"
  period: 1m  # 采集间隔,可按需调整
  index_patterns: [".ds-elastic-cloud-logs*"]

启动Metricbeat后,它会将索引的大小等指标写入metricbeat-*索引中。

2. 创建Kibana告警规则

  • 进入Kibana的「告警」页面,选择「创建规则」,规则类型选Index Threshold
  • 索引模式选择metricbeat-*,时间字段选@timestamp
  • 分组字段选择elasticsearch.index.name(确保能匹配目标索引)
  • 指标统计方式选Sum,字段选择elasticsearch.index.store.size.bytes
  • 设置阈值条件,比如「当总和超过10GB(即1010241024*1024字节)时触发」
  • 配置通知渠道(邮件、Slack等)后完成规则创建

方案二:使用Elasticsearch原生Watcher

直接通过Watcher编写告警逻辑,无需额外采集工具:

1. 创建Watcher规则

执行以下ES请求创建监控Watcher:

PUT _watcher/watch/index_size_alert
{
  "trigger": {
    "schedule": {
      "interval": "1m"  // 检查间隔
    }
  },
  "input": {
    "http": {
      "request": {
        "method": "GET",
        "path": "/.ds-elastic-cloud-logs*/_stats",
        "hosts": ["http://你的ES地址:9200"],
        "auth": {
          "username": "你的用户名",
          "password": "你的密码"
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload._all.primaries.store.size_in_bytes": {
        "gt": 10737418240  // 替换成你的阈值字节数,示例为10GB
      }
    }
  },
  "actions": {
    "send_alert_email": {
      "email": {
        "to": ["你的邮箱@xxx.com"],
        "subject": "索引大小超出阈值告警",
        "body": "索引模式 .ds-elastic-cloud-logs* 总大小已超过10GB,当前大小:{{ ctx.payload._all.primaries.store.size_in_bytes }} 字节"
      }
    }
  }
}

2. 验证与测试

  • 查看Watcher配置:GET _watcher/watch/index_size_alert
  • 手动触发测试:POST _watcher/watch/index_size_alert/_execute

内容的提问来源于stack exchange,提问作者Marina

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 00:32:17