如何在Elasticsearch Fleet有新Agent加入时获取告警通知?
解决方案:监控Fleet Agent新增并触发自有应用通知
方法1:使用Elasticsearch Watcher监控fleet-agents索引
Fleet的所有Agent元数据都存储在fleet-agents索引中,新Agent加入时会在此索引中新增一条文档。你可以通过Watcher配置监控任务,检测该索引的新增文档,再触发HTTP请求通知自有应用。
步骤1:创建Watcher
以下是示例Watcher配置,每5分钟检查一次fleet-agents索引中过去5分钟内新增的Agent,并将信息通过POST请求发送到你的自有应用接口:
PUT _watcher/watch/fleet_new_agent_alert { "trigger": { "schedule": { "interval": "5m" } }, "input": { "search": { "request": { "indices": ["fleet-agents"], "body": { "query": { "range": { "@timestamp": { "gte": "now-5m", "lte": "now" } } }, "size": 100 } } } }, "condition": { "compare": { "ctx.payload.hits.total.value": { "gt": 0 } } }, "actions": { "notify_my_app": { "webhook": { "method": "POST", "url": "https://your-own-app.com/api/fleet-agent-notify", "body": { "new_agents": "{{#ctx.payload.hits.hits}}{{_source.agent.name}} (ID: {{_source.agent.id}}, Enrolled at: {{_source.enrolled_at}}){{^last}}, {{/last}}{{/ctx.payload.hits.hits}}", "count": "{{ctx.payload.hits.total.value}}" }, "headers": { "Content-Type": "application/json" } } } } }
关键说明
trigger:设置检查频率,可根据需求调整间隔时长。input:查询fleet-agents索引中最近5分钟的新增文档(新Agent注册时会自动填充@timestamp字段)。condition:仅当查询到新增Agent(总命中数大于0)时,才触发后续动作。actions:通过webhook发送POST请求到自有应用接口,请求体包含新增Agent的名称、ID和注册时间等信息,可根据自有应用需求调整结构。
验证Watcher
创建完成后,可手动触发测试:
POST _watcher/watch/fleet_new_agent_alert/_execute
方法2:使用Elasticsearch Ingest Pipeline(实时触发)
如果需要更实时的通知,可配置Ingest Pipeline,当fleet-agents索引新增文档时自动调用自有应用接口。
步骤1:创建Ingest Pipeline
PUT _ingest/pipeline/fleet-agent-notify-pipeline { "processors": [ { "webhook": { "url": "https://your-own-app.com/api/fleet-agent-notify", "method": "POST", "body": "{\"agent_name\": \"{{agent.name}}\", \"agent_id\": \"{{agent.id}}\", \"enrolled_at\": \"{{enrolled_at}}\"}", "headers": { "Content-Type": "application/json" } } } ] }
步骤2:关联到fleet-agents索引的默认Pipeline
修改fleet-agents索引设置,将上述Pipeline设为默认:
PUT fleet-agents/_settings { "index.default_pipeline": "fleet-agent-notify-pipeline" }
此后,每当有新Agent注册并写入fleet-agents索引时,Pipeline会自动触发Webhook请求,实时通知自有应用。
注意事项
- 确保Elasticsearch集群可访问自有应用接口,如有网络限制需配置对应规则。
- 可在Webhook的headers中添加
Authorization字段,保障接口安全。 - 对于Watcher,需配置其执行权限,确保能访问
fleet-agents索引并发送Webhook请求。
内容的提问来源于stack exchange,提问作者Krishna Teja
相关产品推荐
相关产品推荐

