Open callahan22 opened 6 years ago
After a day of fiddling with elastalert, I've finally got it installed. Looks like it needs Python 2.7. Unless I've been blind, I didn't see this mentioned anywhere in the documentation. Feel free to link me to somewhere it does that I've missed. While far from complete, hopefully this should be enough to save someone else a full day of head scratching...
Windows 2012
Open the rules/example_frequency.yaml file and change the following entries:
**es_host:** _enter your ES server or round robin DNS name for your cluster here
**es_port:** 9200
**index:** one_of_your_indexes-*
**filter:** Use the reference here: http://elastalert.readthedocs.io/en/latest/recipes/writing_filters.html
Once those are saved, you can go back to your Powershell window and run the following to test your filter:
That should give you some useful feedback and at least get things moving. This obviously doesn't cover adding the elastalert index into your ES cluster. These steps should bring you up to the "Setting up Elasticsearch" section of the official guide: http://elastalert.readthedocs.io/en/latest/running_elastalert.html#downloading-and-configuring
there are no scripts directory in the python directory and the pip is not out there where did you download your python?
Hi Orman, take the latest minor release of python 2.7. In my case today it was 2.7.15.
@callahan22 looking at the issue the problem with blist file better to download the appropriate wheel file from this link and run it. blist_wheel
Hi,
I can't find any documentation for a Windows install that works. I've got a working ES cluster. I'm installing onto the first Elastic node in the cluster. I know I need the VC++ 2015.3 v140 toolset for desktop (x86,x64) installed so I've installed it.
Following the installation instructions step by step, I run: pip install elastalert - it fails. The output is as follows: