【问题标题】:Email notification from Graylog2来自 Graylog2 的电子邮件通知
【发布时间】:2013-02-04 14:20:34
【问题描述】:

我的客户设置了 Greylog2 服务器来汇总我们的日志文件。我们定义了几个流。

我希望每天发送电子邮件通知 - 至少“系统在过去 24 小时内收到 x 个错误”,最好是前十个最常见错误的列表。

以前有没有人实现过类似的东西 - 你能提供任何提示或建议吗?我在一些论坛帖子中看到提到了 REST api,但找不到更多信息...

【问题讨论】:

    标签: logging graylog2


    【解决方案1】:

    在我的工作场所,我们配置了基于 rake 任务 + crontab 的警报任务。这是在 graylog2-server 中的警报 API 可用之前 (plugin directory)。我们仍然使用 rake 任务,因为它们让我们可以使用 rails 模型和控制器。

    将以下内容添加到general.yaml中,以便我们可以找到流ID。

    # section in general.yaml
    
    streamalarms:
      error_stream: 50ef145471de3516b900000d
    

    以下是实际的rake任务:

    namespace :gl2rake
    
        # Helper method for recording how long jobs took, which is used to debug / tune the jobs.
        def monitoring_wrapper(task)
        btime = Time.now
        task_name = task.name
        task_starting(task_name)
    
        if block_given?
          yield
        else 
          puts "No block given to monitoring_wrapper!"
        end
    
        etime = Time.now
        duration = (etime - btime)
        puts "Time elapsed: #{duration} seconds"
        task_completed(task_name, duration)
      end
    
        desc "Send an email if a job is written to the error queue. If there are more than 5 errored jobs in the last 6 minutes then send sms"
      task :error_queue => :environment do |task|
        monitoring_wrapper(task) do
    
          # the streams to check
          # I have customised the configuration class so that all of the stream ids are available. This can be automated.
          streams = Configuration.streamalarm_config('error_stream', '')
    
          # this method has been added to app/models/configuration.rb as a convenience.
          # def self.streamalarm_config(key, default)
          #   nested_general_config :streamalarms, key, default
          # end
    
          # get unix epoch time of 6 minutes ago
          six_mins_ago = 6.minutes.ago
    
          filters = {
            # optionally apply a message filter to the stream
            :message => "\"Writing job to error queue.\"",
            :date => "from #{six_mins_ago}" 
          }
    
          # get the stream
          stream = Stream.find_by_id(stream_id)
    
          if !stream
            $stderr.puts "Invalid stream id #{stream_id}"
            next
          end
    
          messages = MessageGateway.all_by_quickfilter(filters, nil, {:stream_id => stream_id})
    
          if messages.size > 0
    
            #alert - jobs written to error queue
            if messages.size > 5
                # send_sms_for_stream is a custom method we wrote that hooks into an sms api.
              send_sms_for_stream("There are #{messages.size} errored job(s) in the last 6 minutes. Check email for details", 'error_queue', stream.title)
            end
    
            message = "There are #{messages.size} errored job(s) in the last 6 minutes. (Stream #{stream.title})\n"
    
            messages.each do |m|
              message += "\t#{m.message}\n"
            end
    
            # sends an email to our designated alerting email
            send_mail("There are  #{messages.size} errored job(s)", message, 'error_queue', stream.title)
          end
        end
      end
    end
    

    现在可以通过 cron 作业调用它:例如

    3-59/5 * * * * sudo rake -f /opt/graylog2-web-interface/Rakefile gl2rake:error_queue RAILS_ENV=production
    

    【讨论】:

      猜你喜欢
      • 2017-10-10
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2014-06-05
      • 1970-01-01
      • 2016-11-03
      • 1970-01-01
      • 1970-01-01
      相关资源
      最近更新 更多