You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Elastic Watcher无法附加文档:如何在邮件告警中添加实际文档?

在Elastic Cloud Watcher邮件告警中附加实际Packetbeat文档

我来帮你解决这个问题,咱们分场景处理,同时也会排查你之前遇到的报表报错问题:

一、直接在邮件中展示少量实际文档

如果告警触发时需要附加的文档数量不多(比如前10条),可以直接修改Watcher的查询逻辑,把实际文档数据带回,再在邮件模板里渲染出来:

  1. 调整Watcher的Input部分
    在原有的计数查询基础上,用chain input同时获取文档列表和计数:

    "input": {
      "chain": [
        {
          "search": {
            "request": {
              "indices": ["packetbeat-*"],
              "body": {
                "size": 10, // 限制返回的文档数量
                "query": {
                  "bool": {
                    "filter": [
                      {
                        "range": {
                          "@timestamp": {
                            "gte": "now-1h",
                            "lte": "now"
                          }
                        }
                      }
                    ]
                  }
                }
              }
            }
          }
        },
        {
          "search": {
            "request": {
              "indices": ["packetbeat-*"],
              "body": {
                "size": 0,
                "aggs": {
                  "doc_count": {
                    "value_count": {
                      "field": "_id"
                    }
                  }
                },
                "query": {
                  "bool": {
                    "filter": [
                      {
                        "range": {
                          "@timestamp": {
                            "gte": "now-1h",
                            "lte": "now"
                          }
                        }
                      }
                    ]
                  }
                }
              }
            }
          }
        }
      ]
    }
    
  2. 修改邮件Action的内容模板
    在邮件正文中添加文档内容的渲染:

    "actions": {
      "send_email": {
        "email": {
          "to": ["your-email@example.com"],
          "subject": "Packetbeat文档告警 - 过去1小时共{{ctx.payload.1.aggregations.doc_count.value}}条",
          "body": "<h3>过去1小时文档计数:{{ctx.payload.1.aggregations.doc_count.value}}</h3><h4>最新10条文档:</h4><ul>{{#ctx.payload.0.hits.hits}}<li>{{_source}}</li>{{/ctx.payload.0.hits.hits}}</ul>"
        }
      }
    }
    

    用Mustache模板遍历第一个查询返回的文档列表,把每个文档的原始内容展示出来。

二、导出为CSV附件(适合大量文档)

如果需要附加较多文档,推荐生成CSV附件,步骤如下:

在Watcher的Action中配置CSV附件,用Mustache模板拼接表头和内容:

"actions": {
  "send_email": {
    "email": {
      "to": ["your-email@example.com"],
      "subject": "Packetbeat文档告警 - 过去1小时共{{ctx.payload.aggregations.doc_count.value}}条",
      "body": "过去1小时Packetbeat文档计数:{{ctx.payload.aggregations.doc_count.value}},附件为详细文档列表",
      "attachments": {
        "packetbeat_docs.csv": {
          "data": {
            "format": "csv",
            "source": "timestamp,source_ip,dest_ip,message\n{{#ctx.payload.hits.hits}}{{_source.@timestamp}},{{_source.source.ip}},{{_source.destination.ip}},{{_source.message}}\n{{/ctx.payload.hits.hits}}"
          }
        }
      }
    }
  }
}

你可以根据Packetbeat的实际字段调整表头和内容字段,确保和你的文档结构匹配。

三、排查“报表未找到”的错误

之前尝试发送可视化报表报错,大概率是这几个原因:

  • 报表ID不正确:在Kibana创建报表后,要确认Watcher中引用的report_id和报表URL里的ID完全一致。
  • 权限不足:Watcher使用的服务账号需要拥有reporting_user角色,或者至少有对应索引和报表资源的read权限。
  • 报表未生成完成:如果是实时生成报表,需要确保报表已成功创建,或者配置wait_for_completion: false改用异步生成方式。

内容的提问来源于stack exchange,提问作者shantanuo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 07:33:02