Closed da2vin closed 7 years ago
It looks like your @timestamp has the wrong time zone.
"timestamp" : "1491964113790",
== Wed Apr 12 02:28:33 UTC 2017
2017-04-12T10:28:33.790Z
== Wed Apr 12 10:28:33 UTC 2017
2017-04-12 12:50 CST: 0 / 0 hits
== Wed Apr 12 04:50:33 UTC 2017
The document @timestamp says it comes from the future!!
This might work.
timestamp_field: "@fields.timestamp"
timestamp_type: unix_ms
It works! thank you very much!
Hi Here I have similar problem unable to trace what could be the issue like timestamp or older date which rule just searches current @timestamp. but rule name any should not restrict with stamp it should search for filters applied as both. I can search the data is available in Kibana but with ElastAlert it shows 0 hits, 0 alerts 0 sent.
Elastic Data
http://localhost:9200/sw/_search?q=name:Solo
rule es_host: localhost es_port: 9200 name: Test2 rule type: any index: sw timestamp_field: created timestamp_type: iso num_events: 1 timeframe: hours: 0.1 filter:
console output
C:\Python27\Scripts>python -m elastalert.elastalert --verbose --rule test2.yaml INFO:elastalert:Starting up INFO:elastalert:Sleeping for 59.985 seconds
INFO:elastalert:Queried rule local test rule from 2015-12-12 17:49 India Standar d Time to 2015-12-12 18:04 India Standard Time: 0 / 0 hits INFO:elastalert:Queried rule local test rule from 2015-12-12 18:04 India Standar d Time to 2015-12-12 18:19 India Standard Time: 0 / 0 hits INFO:elastalert:Queried rule local test rule from 2015-12-12 18:19 India Standar d Time to 2015-12-12 18:34 India Standard Time: 0 / 0 hits INFO:elastalert:Queried rule local test rule from 2015-12-12 18:34 India Standar d Time to 2015-12-12 18:49 India Standard Time: 0 / 0 hits INFO:elastalert:Queried rule local test rule from 2015-12-12 18:49 India Standar d Time to 2015-12-12 19:04 India Standard Time: 0 / 0 hits INFO:elastalert:Queried rule local test rule from 2015-12-12 19:04 India Standar d Time to 2015-12-12 19:19 India Standard Time: 0 / 0 hits INFO:elastalert:Queried rule local test rule from 2015-12-12 19:19 India Standar d Time to 2015-12-12 19:34 India Standard Time: 0 / 0 hits INFO:elastalert:Queried rule local test rule from 2015-12-12 19:34 India Standar d Time to 2015-12-12 19:49 India Standard Time: 0 / 0 hits INFO:elastalert:Queried rule local test rule from 2015-12-12 19:49 India Standar d Time to 2015-12-12 20:04 India Standard Time: 0 / 0 hits INFO:elastalert:Queried rule local test rule from 2015-12-12 20:04 India Standar d Time to 2015-12-12 20:19 India Standard Time: 0 / 0 hits INFO:elastalert:Queried rule local test rule from 2015-12-12 20:19 India Standar d Time to 2015-12-12 20:34 India Standard Time: 0 / 0 hits INFO:elastalert:Queried rule local test rule from 2015-12-12 20:34 India Standar d Time to 2015-12-12 20:49 India Standard Time: 0 / 0 hits INFO:elastalert:Queried rule local test rule from 2015-12-12 20:49 India Standar d Time to 2015-12-12 21:04 India Standard Time: 0 / 0 hits INFO:elastalert:Queried rule local test rule from 2015-12-12 21:04 India Standar d Time to 2015-12-12 21:19 India Standard Time: 0 / 0 hits INFO:elastalert:Queried rule local test rule from 2015-12-12 21:19 India Standar d Time to 2015-12-12 21:34 India Standard Time: 0 / 0 hits INFO:elastalert:Queried rule local test rule from 2015-12-12 21:34 India Standar d Time to 2015-12-12 21:49 India Standard Time: 0 / 0 hits INFO:elastalert:Queried rule local test rule from 2015-12-12 21:49 India Standar d Time to 2015-12-12 22:04 India Standard Time: 0 / 0 hits INFO:elastalert:Queried rule local test rule from 2015-12-12 22:04 India Standar d Time to 2015-12-12 22:19 India Standard Time: 0 / 0 hits INFO:elastalert:Skipping writing to ES: {'hits': 0, 'matches': 0, '@timestamp': '2017-10-16T17:57:21.976Z', 'rule_name': 'local test rule', 'starttime': '2014-1 2-10T16:49:00Z', 'endtime': '2015-12-12T16:49:00Z', 'time_taken': 115.3900001049 0417} INFO:elastalert:Ran local test rule from 2014-12-10 22:19 India Standard Time to 2015-12-12 22:19 India Standard Time: 0 query hits (0 already seen), 0 matches, 0 alerts sent WARNING:root:Querying from 2014-12-10 22:19 India Standard Time to 2015-12-12 22 :19 India Standard Time took longer than 0:01:00!
Hello!
I used elastalert-test-rule but 0 query hits:
sqoop_alert.yaml:
elasticsearch index :
sqoop-2017-04-12
index info:
I changed another index and successed,but this index failed,I don't know why...please help~~~~