Open zhangyuxuan1992 opened 3 years ago
raise
EAException("Could not parse filter %s for Kibana" % (es_filter))', "elastalert.util.EAException: Could not parse filter {'query_string': {'query': 'loglevel: ERROR'}} for Kibana"]}`
my question is this error
so is there generate_kibana_link for es 7?
@nsano-rururu. Then how to generate_kibana_link for es 7. elastalert only support for es3 and es 4? If support es 7 means can you share an example here, please. Thank you did you solve this problem @zhangyuxuan1992 ?
Thank you @nsano-rururu Finally, I changed like this. It's working fine.
name: Example frequency rule
type: frequency
index: audit-log-*
num_events: 1
timeframe:
minutes: 5
filter:
- query:
query_string:
query: "applicationname.keyword: SRTransform"
alert:
- "email"
email:
- "abcd@gmail.com"
from_addr: "no-reply@elastalert.com"
email_reply_to: "no-reply@elastalert.com"
aggregation:
minutes: 2
alert_text_type: alert_text_only
alert_text: "Generated link to kibana: {0}"
alert_text_args: ["kibana_link"]
# Kibana
kibana_url: http://x.x.x.x:5601/app/kibana
use_kibana4_dashboard: "http://x.x.x.x:5601/app/kibana#/dashboard/78bce050-a193-11ea-ab49-e5346031d124"
NOTE: 78bce050-a193-11ea-ab49-e5346031d124 is Dashboard ID.
rule config:
ERROR :