Elastic Watcher无法附加文档:如何在邮件告警中添加实际文档?
在Elastic Cloud Watcher邮件告警中附加实际Packetbeat文档
我来帮你解决这个问题,咱们分场景处理,同时也会排查你之前遇到的报表报错问题:
一、直接在邮件中展示少量实际文档
如果告警触发时需要附加的文档数量不多(比如前10条),可以直接修改Watcher的查询逻辑,把实际文档数据带回,再在邮件模板里渲染出来:
调整Watcher的Input部分
在原有的计数查询基础上,用chaininput同时获取文档列表和计数:"input": { "chain": [ { "search": { "request": { "indices": ["packetbeat-*"], "body": { "size": 10, // 限制返回的文档数量 "query": { "bool": { "filter": [ { "range": { "@timestamp": { "gte": "now-1h", "lte": "now" } } } ] } } } } } }, { "search": { "request": { "indices": ["packetbeat-*"], "body": { "size": 0, "aggs": { "doc_count": { "value_count": { "field": "_id" } } }, "query": { "bool": { "filter": [ { "range": { "@timestamp": { "gte": "now-1h", "lte": "now" } } } ] } } } } } } ] }修改邮件Action的内容模板
在邮件正文中添加文档内容的渲染:"actions": { "send_email": { "email": { "to": ["your-email@example.com"], "subject": "Packetbeat文档告警 - 过去1小时共{{ctx.payload.1.aggregations.doc_count.value}}条", "body": "<h3>过去1小时文档计数:{{ctx.payload.1.aggregations.doc_count.value}}</h3><h4>最新10条文档:</h4><ul>{{#ctx.payload.0.hits.hits}}<li>{{_source}}</li>{{/ctx.payload.0.hits.hits}}</ul>" } } }用Mustache模板遍历第一个查询返回的文档列表,把每个文档的原始内容展示出来。
二、导出为CSV附件(适合大量文档)
如果需要附加较多文档,推荐生成CSV附件,步骤如下:
在Watcher的Action中配置CSV附件,用Mustache模板拼接表头和内容:
"actions": { "send_email": { "email": { "to": ["your-email@example.com"], "subject": "Packetbeat文档告警 - 过去1小时共{{ctx.payload.aggregations.doc_count.value}}条", "body": "过去1小时Packetbeat文档计数:{{ctx.payload.aggregations.doc_count.value}},附件为详细文档列表", "attachments": { "packetbeat_docs.csv": { "data": { "format": "csv", "source": "timestamp,source_ip,dest_ip,message\n{{#ctx.payload.hits.hits}}{{_source.@timestamp}},{{_source.source.ip}},{{_source.destination.ip}},{{_source.message}}\n{{/ctx.payload.hits.hits}}" } } } } } }
你可以根据Packetbeat的实际字段调整表头和内容字段,确保和你的文档结构匹配。
三、排查“报表未找到”的错误
之前尝试发送可视化报表报错,大概率是这几个原因:
- 报表ID不正确:在Kibana创建报表后,要确认Watcher中引用的
report_id和报表URL里的ID完全一致。 - 权限不足:Watcher使用的服务账号需要拥有
reporting_user角色,或者至少有对应索引和报表资源的read权限。 - 报表未生成完成:如果是实时生成报表,需要确保报表已成功创建,或者配置
wait_for_completion: false改用异步生成方式。
内容的提问来源于stack exchange,提问作者shantanuo
相关产品推荐
相关产品推荐

