You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Elastalert邮件告警中使用文档字段值作为收件地址?

Dynamic Email Recipients from Elasticsearch Document Fields in Elastalert

Absolutely! You can dynamically pull the mail_to field value from your matching Elasticsearch documents to send alerts, instead of hardcoding email addresses. Elastalert supports template variables that let you reference fields directly from the matched hits, which makes this straightforward.

Modified Rule Configuration

Here's how to adjust your existing rule to use the mail_to field as the recipient:

name: email blacklist rule
type: blacklist
index: subjects
compare_key: subject
blacklist:
  - "Hindi"
alert:
  - "email"
email:
  - "{match[mail_to]}"  # Dynamically uses the mail_to value from the matching document
# Optional: Customize alert subject/text with document fields
alert_subject: "Blacklist Alert: {match[subject]} Detected"
alert_text: |
  A blacklisted subject was found in your Elasticsearch index:
  - Subject: {match[subject]}
  - Timestamp: {match[@timestamp]}
  - Alert sent to: {match[mail_to]}

How It Works

  • The {match[field_name]} syntax tells Elastalert to pull the value of field_name from the document that triggered the alert. In your case, {match[mail_to]} will be replaced with sample@gmail.com when the document with subject: "Hindi" is matched.
  • You can use this same template syntax in the alert_subject and alert_text fields to include other relevant data from the document, making your alerts more informative.

Key Notes

  1. Field Existence: Make sure every document that might trigger this alert has a mail_to field. If some documents are missing it, you can set a default fallback address using:
    email:
      - "{match[mail_to]|fallback@example.com}"
    
  2. Testing: Use the elastalert-test-rule command to verify your configuration works as expected. This will show you exactly how the alert will be formatted, including the dynamic recipient.
  3. Elastalert Version: This template functionality is supported in most recent versions of Elastalert, so ensure you're running a version that includes this feature.

内容的提问来源于stack exchange,提问作者rana bhagath chand

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.08 20:58:00