You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Elasticsearch Fleet有新Agent加入时获取告警通知?

解决方案:监控Fleet Agent新增并触发自有应用通知

方法1:使用Elasticsearch Watcher监控fleet-agents索引

Fleet的所有Agent元数据都存储在fleet-agents索引中,新Agent加入时会在此索引中新增一条文档。你可以通过Watcher配置监控任务,检测该索引的新增文档,再触发HTTP请求通知自有应用。

步骤1:创建Watcher

以下是示例Watcher配置,每5分钟检查一次fleet-agents索引中过去5分钟内新增的Agent,并将信息通过POST请求发送到你的自有应用接口:

PUT _watcher/watch/fleet_new_agent_alert
{
  "trigger": {
    "schedule": {
      "interval": "5m"
    }
  },
  "input": {
    "search": {
      "request": {
        "indices": ["fleet-agents"],
        "body": {
          "query": {
            "range": {
              "@timestamp": {
                "gte": "now-5m",
                "lte": "now"
              }
            }
          },
          "size": 100
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.total.value": {
        "gt": 0
      }
    }
  },
  "actions": {
    "notify_my_app": {
      "webhook": {
        "method": "POST",
        "url": "https://your-own-app.com/api/fleet-agent-notify",
        "body": {
          "new_agents": "{{#ctx.payload.hits.hits}}{{_source.agent.name}} (ID: {{_source.agent.id}}, Enrolled at: {{_source.enrolled_at}}){{^last}}, {{/last}}{{/ctx.payload.hits.hits}}",
          "count": "{{ctx.payload.hits.total.value}}"
        },
        "headers": {
          "Content-Type": "application/json"
        }
      }
    }
  }
}

关键说明

  • trigger:设置检查频率,可根据需求调整间隔时长。
  • input:查询fleet-agents索引中最近5分钟的新增文档(新Agent注册时会自动填充@timestamp字段)。
  • condition:仅当查询到新增Agent(总命中数大于0)时,才触发后续动作。
  • actions:通过webhook发送POST请求到自有应用接口,请求体包含新增Agent的名称、ID和注册时间等信息,可根据自有应用需求调整结构。

验证Watcher

创建完成后,可手动触发测试:

POST _watcher/watch/fleet_new_agent_alert/_execute

方法2:使用Elasticsearch Ingest Pipeline(实时触发)

如果需要更实时的通知,可配置Ingest Pipeline,当fleet-agents索引新增文档时自动调用自有应用接口。

步骤1:创建Ingest Pipeline

PUT _ingest/pipeline/fleet-agent-notify-pipeline
{
  "processors": [
    {
      "webhook": {
        "url": "https://your-own-app.com/api/fleet-agent-notify",
        "method": "POST",
        "body": "{\"agent_name\": \"{{agent.name}}\", \"agent_id\": \"{{agent.id}}\", \"enrolled_at\": \"{{enrolled_at}}\"}",
        "headers": {
          "Content-Type": "application/json"
        }
      }
    }
  ]
}

步骤2:关联到fleet-agents索引的默认Pipeline

修改fleet-agents索引设置,将上述Pipeline设为默认:

PUT fleet-agents/_settings
{
  "index.default_pipeline": "fleet-agent-notify-pipeline"
}

此后,每当有新Agent注册并写入fleet-agents索引时,Pipeline会自动触发Webhook请求,实时通知自有应用。

注意事项

  • 确保Elasticsearch集群可访问自有应用接口,如有网络限制需配置对应规则。
  • 可在Webhook的headers中添加Authorization字段,保障接口安全。
  • 对于Watcher,需配置其执行权限,确保能访问fleet-agents索引并发送Webhook请求。

内容的提问来源于stack exchange,提问作者Krishna Teja

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.15 01:10:28