You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于Elasticsearch与Kibana告警实现物体越线检测的技术问询

实现船只穿越预设地理线条的检测方案

一、确认预设线条的索引结构

先验证你创建的线条索引中,地理字段为geo_shape类型的LineString,避免后续查询报错。执行以下Elasticsearch查询:

GET /你的线条索引名/_mapping

返回结果需包含类似结构:

"geometry": {
  "type": "geo_shape",
  "strategy": "recursive"
}

二、构建穿越检测的Elasticsearch查询

船只位置是带时间戳的序列数据,核心逻辑是检测相邻时间点的船只位置线段是否与预设线条交叉,用ES地理空间函数ST_Crosses实现。

假设你的船只数据索引为vessel-data,位置字段location(geo_point类型)、时间字段timestamp;预设线条索引为boundary-line,线条字段line_geom(geo_shape类型),可使用以下查询模板:

GET /vessel-data/_search
{
  "size": 0,
  "query": {
    "bool": {
      "must": [
        {
          "range": {
            "timestamp": {
              "gte": "now-1h",
              "lt": "now"
            }
          }
        }
      ]
    }
  },
  "aggs": {
    "vessels": {
      "terms": {
        "field": "vessel_id.keyword"
      },
      "aggs": {
        "sorted_locations": {
          "top_hits": {
            "size": 2,
            "sort": [{"timestamp": "asc"}]
          }
        },
        "crosses_boundary": {
          "bucket_script": {
            "buckets_path": {
              "loc1": "sorted_locations.hits.hits.0._source.location",
              "loc2": "sorted_locations.hits.hits.1._source.location",
              "boundary": "/boundary-line/_doc/你的线条ID/_source.line_geom"
            },
            "script": """
              def line1 = LineStringBuilder.new().add(new Point(loc1.lon, loc1.lat)).add(new Point(loc2.lon, loc2.lat)).build();
              def boundaryLine = ShapeBuilder.parse(boundary);
              return line1.crosses(boundaryLine);
            """
          }
        }
      }
    }
  }
}

该查询按船只ID分组,取最近两个时间点的位置生成线段,判断是否与预设线条交叉,返回存在交叉的船只分组。

三、配置Kibana规则实现警报

  1. 进入Kibana的Stack Management > Rules and Connectors,点击Create rule
  2. 选择Custom query规则类型
  3. 在Query区域粘贴上述ES查询,调整时间范围(比如设置为每5分钟检测最近10分钟的数据)
  4. 在Alert conditions中设置:当aggregations.vessels.buckets的长度大于0时触发警报(即存在穿越的船只)
  5. 配置Actions,比如发送邮件、Slack通知或写入日志索引
  6. 保存规则,设置执行频率(比如每5分钟运行一次)

四、性能优化建议

  • 给vessel_id和timestamp字段创建复合索引,提升分组查询速度
  • 通过Ingest Pipeline实时更新船只索引的last_location字段,减少聚合时的top_hits查询开销
  • 若有多段预设线条,将所有线条存入同一索引,查询时匹配所有线条的交叉情况

内容的提问来源于stack exchange,提问作者user56564

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.31 23:45:23