Has match but not alert? #2792

Open chisijun opened 4 years ago

chisijun commented 4 years ago

hello, i config rule match hits but not email alert。 WARNING:apscheduler.scheduler:Execution of job "ElastAlerter.handle_pending_alerts (trigger: interval[0:01:00], next run at: 2020-05-09 14:41:35 CST)" skipped: maximum number of running instances reached (1)

chisijun commented 4 years ago

INFO:elastalert:Background configuration change check run at 2020-05-09 14:38 CST INFO:elastalert:Disabled rules are: [] INFO:elastalert:Sleeping for 59.999853 seconds INFO:elastalert:Queried rule Nginx_err from 2020-05-09 14:33 CST to 2020-05-09 14:38 CST: 2 / 2 hits INFO:elastalert:Adding alert for Nginx_err to aggregation(id: VWkn-HEByoHdF7eIfW3m, aggregation_key: None), next alert at 2020-05-09 06:37:59.925795+00:00 INFO:elastalert:Ran Nginx_err from 2020-05-09 14:33 CST to 2020-05-09 14:38 CST: 2 query hits (1 already seen), 1 matches, 0 alerts sent WARNING:apscheduler.scheduler:Execution of job "ElastAlerter.handle_pending_alerts (trigger: interval[0:01:00], next run at: 2020-05-09 14:39:35 CST)" skipped: maximum number of running instances reached (1) INFO:elastalert:Background configuration change check run at 2020-05-09 14:39 CST INFO:elastalert:Disabled rules are: [] INFO:elastalert:Sleeping for 59.99985 seconds INFO:elastalert:Queried rule Nginx_err from 2020-05-09 14:33 CST to 2020-05-09 14:39 CST: 2 / 2 hits INFO:elastalert:Ran Nginx_err from 2020-05-09 14:33 CST to 2020-05-09 14:39 CST: 2 query hits (2 already seen), 0 matches, 0 alerts sent

rehannali commented 4 years ago

@chisijun , Hi, Could you provide us more details so we can see what's wrong? It didn't mentioned that it matched with query.

jwh5566 commented 4 years ago

+1 has match but not send email

INFO:elastalert:Sleeping for 119.999933 seconds INFO:elastalert:Queried rule Example frequency rule from 2020-05-27 15:02 CST to 2020-05-27 15:17 CST: 73 / 73 hits INFO:elastalert:Queried rule Example frequency rule from 2020-05-27 15:17 CST to 2020-05-27 15:32 CST: 144 / 144 hits INFO:elastalert:Queried rule Example frequency rule from 2020-05-27 15:32 CST to 2020-05-27 15:47 CST: 84 / 84 hits INFO:elastalert:Queried rule Example frequency rule from 2020-05-27 15:47 CST to 2020-05-27 16:02 CST: 31 / 31 hits INFO:elastalert:Queried rule Example frequency rule from 2020-05-27 16:02 CST to 2020-05-27 16:17 CST: 104 / 104 hits INFO:elastalert:Queried rule Example frequency rule from 2020-05-27 16:17 CST to 2020-05-27 16:32 CST: 50 / 50 hits INFO:elastalert:Queried rule Example frequency rule from 2020-05-27 16:32 CST to 2020-05-27 16:41 CST: 27 / 27 hits INFO:elastalert:Background configuration change check run at 2020-05-27 16:43 CST INFO:elastalert:Background alerts thread 0 pending alerts sent at 2020-05-27 16:43 CST INFO:elastalert:Disabled rules are: [] INFO:elastalert:Sleeping for 119.999904 seconds WARNING:apscheduler.scheduler:Execution of job "ElastAlerter.handle_rule_execution (trigger: interval[0:02:00], next run at: 2020-05-27 16:43:55 CST)" skipped: maximum number of running instances reached (1)

yinhejianke commented 4 years ago

WARNING:apscheduler.scheduler:Execution of job "ElastAlerter.handle_rule_execution (trigger: interval[0:01:00], next run at: 2020-09-02 07:52:53 UTC)" skipped: maximum number of running instances reached (1)

need help !!!!

mengsir99 commented 4 years ago

WARNING:apscheduler.scheduler:Execution of job "ElastAlerter.handle_rule_execution (trigger: interval[0:01:00], next run at: 2020-09-02 07:52:53 UTC)" skipped: maximum number of running instances reached (1)

need help !!!!

Have you solved it,I also met

yinhejianke commented 4 years ago

Try The Email send OK ? I find my email not send info .

ramprasadavirineni commented 3 years ago


Could you please provide any fixes on below issue....I am not getting emails.

INFO:elastalert:Disabled rules are: [] INFO:elastalert:Sleeping for 59.999718 seconds INFO:elastalert:Queried rule Hello Test mail from ELK Stack please ignore from 2021-04-23 08:04 EDT to 2021-04-23 08:19 EDT: 0 / 0 hits INFO:elastalert:Ran Hello Test mail from ELK Stack please ignore from 2021-04-23 08:04 EDT to 2021-04-23 08:19 EDT: 0 query hits (0 already seen), 0 matches, 0 alerts sent ^CINFO:elastalert:SIGINT received, stopping ElastAlert.. ===========================================
