请求生成Kibana Watcher API JSON负载:监控失败日志触发邮件通知
Kibana Watcher API JSON Payload
This JSON payload creates a Kibana Watcher that runs every 5 minutes, checks for failure logs from the DATA-LAMBDA-FUNCTION component, and sends an email with entity-error pairs if any failures are detected.
{ "trigger": { "schedule": { "interval": "5m" } }, "input": { "search": { "request": { "indices": ["your-log-index-pattern*"], "body": { "query": { "bool": { "must": [ { "term": { "srcSystem.componentName": "DATA-LAMBDA-FUNCTION" } }, { "term": { "srcSystem.data.auditJson.job_status": "FAILURE" } }, { "range": { "@timestamp": { "gte": "now-5m", "lte": "now" } } } ] } }, "aggs": { "failures": { "terms": { "field": "srcSystem.data.auditJson.entityName.keyword", "size": 100 }, "aggs": { "latest_error": { "top_hits": { "size": 1, "_source": { "includes": ["srcSystem.data.auditJson.errorMessage"] }, "sort": [{"@timestamp": "desc"}] } } } } } } } } }, "condition": { "compare": { "ctx.payload.hits.total": { "gt": 0 } } }, "actions": { "send_email": { "email": { "to": ["recipient@example.com"], "subject": "Data Lambda Function Failure Alert", "body": { "text": "The following entities have failed jobs in the last 5 minutes:\n\n{{#ctx.payload.aggregations.failures.buckets}}- Entity: {{key}}\n Error Message: {{latest_error.hits.hits.0._source.srcSystem.data.auditJson.errorMessage}}\n{{/ctx.payload.aggregations.failures.buckets}}" } } } }, "metadata": { "xpack": { "watcher": { "title": "Data Lambda Failure Monitor" } } } }
Important Adjustments:
- Replace
your-log-index-pattern*with the actual index pattern of your log data. - Update
recipient@example.comto the target email address(es) for alerts. - The aggregation groups failures by
entityNameand fetches the latest error message per entity to avoid redundant entries in the email. - The condition ensures the email is only sent if at least one failure log exists in the 5-minute window.
内容的提问来源于stack exchange,提问作者MKumar
相关产品推荐
相关产品推荐

