ELK Notları

ES Query DSL

DSL: domain specific language

Kibana

ES’in index’lediği field’lar; senin örneğin kibana > integrations’ta sample data’da eklediğin field’lar oluyor.

Alerting

Rule types: built in (stack) rules, registered by one of kibana apps. you can create following type of rules;

Create and manage rules

Rule  generated  alerts


------
  Timestamp: |

  Username: 
  Event ID: 
  Event Message: 

{
    "alert_id": "",
    "alert_name": "",
    "alert_instance_id": "",
    "context_title": "",
    "context_value": "",
    "context_message": ""
}
Elasticsearch query rule'' is active:

- Value: 
- Service:   
- Error Message:   
- Document ID:    
- Conditions Met:  over 
- Timestamp: 

https://github.com/elastic/kibana/blob/main/x-pack/plugins/triggers_actions_ui/README.md