ElastAlert 실행

(myvenv) [sooabia@docker-registry ElastAlert]$  nohup elastalert --verbose --rule rule.http.status.404.yaml &


Slack연동 확인

#general

404Log
404Log

@timestamp: 2018-06-28T10:58:05Z
@version: 1
_id: WcILRmQBR-MSP7yUDU0U
_index: accesslog
_type: doc
agent: "User-Agent:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR 1.0.3705"
auth: -
bytes: 214
clientip: 211.141.196.30
host: docker-registry.zerobig.com
httpversion: 1.1
ident: -
message: 211.141.196.30 - - [28/Jun/2018:19:58:05 +0900] "GET /invoker/readonly HTTP/1.1" 404 214 "-" "User-Agent:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR 1.0.3705"
num_hits: 1
num_matches: 1
path: /home/sooabia/apache/logs/access_log
referrer: "-"
request: /invoker/readonly
response: 404
timestamp: 28/Jun/2018:19:58:05 +0900
verb: GET
Show less

  • No labels
Write a comment…