we created one watcher having multiple sourceip so that whenever the watcher matches the messages it will send email alert.
Will it be possible that the watcher having multiple sourceip will send multiple email alerts base on the sourceip that matches the message filter instead of having one email alerts only for all sourceip.
I have attach here the watch definition that we created.
Actually this is for our monitoring and alerting, that everytime the watcher runs it will search for messages per sourceip and send the log details in email per sourceip or per HOST that is actually the logic that we wanted. actually we prefer hostname to be mentioned in the email alert not the IP.
Hope you could assist us, since we were just new to ELK and watcher.
Eventually this alerts will be push to BigPanda.
Thanks in advance, looking forward to hearing from you.
Best regards,
Edward Ian Vera
(Attachment AIX_POC_Watcher_Multiple_Search_IP_err_syslog_ng.txt is missing)
I have attach here the watch definition that we created.
Actually this is for our monitoring and alerting, that everytime the watcher runs it will search for messages per sourceip and send the log details in email per sourceip or per HOST that is actually the logic that we wanted. actually we prefer hostname to be mentioned in the email alert not the IP.
Hope you could assist us, since we were just new to ELK and watcher.
Eventually this alerts will be push to BigPanda.
Thanks in advance, looking forward to hearing from you.
AIX err syslog-ng test alert, I/O error occurred while writing; fd='17', error='No space left on device. If the problem persists, please contact your system administrator (Test Only)</h3>
Thanks for sharing more information @ianvera! Watch actions support a foreach field. I have not tested it, but it sounds like that might help you achieve sending multiple emails per source IP.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.