We designed ElastAlert to be reliable, highly modular, and easy to set up and configure. It works by combining Elasticsearch with two types of components, rule types and alerts. Elasticsearch is periodically queried and the data is passed to the rule type, which determines when a match is found. When a match occurs, it is given to one or more alerts, which take action based on the match. This is configured by a set of rules, each of which defines a query, a rule type, and a set of alerts. Several rule types with common monitoring paradigms are included with ElastAlert. Alerts link to Kibana dashboards. Aggregate counts for arbitrary fields. Combine alerts into periodic reports. Separate alerts by using a unique key field. Intercept and enhance match data. Additional rule types and alerts can be easily imported or written.

Features

  • ElastAlert saves its state to Elasticsearch and, when started, will resume where previously stopped
  • If Elasticsearch is unresponsive, ElastAlert will wait until it recovers before continuing
  • Alerts which throw errors may be automatically retried for a period of time
  • ElastAlert has three main components that may be imported as a module or customized
  • The rule type is responsible for processing the data returned from Elasticsearch
  • Alerts are responsible for taking action based on a match

Project Samples

Project Activity

See All Activity >

Categories

Frameworks

License

Apache License V2.0

Follow ElastAlert

ElastAlert Web Site

Other Useful Business Software
Go From AI Idea to AI App Fast Icon
Go From AI Idea to AI App Fast

One platform to build, fine-tune, and deploy ML models. No MLOps team required.

Access Gemini 3 and 200+ models. Build chatbots, agents, or custom models with built-in monitoring and scaling.
Try Free
Rate This Project
Login To Rate This Project

User Reviews

Be the first to post a review of ElastAlert!

Additional Project Details

Programming Language

Python

Related Categories

Python Frameworks

Registered

2021-07-27