Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- {
- "watch_id": "_inlined_",
- "state": "executed",
- "status": {
- "state": {
- "active": true,
- "timestamp": "2017-10-10T16:57:13.174Z"
- },
- "last_checked": "2017-10-10T16:57:13.174Z",
- "last_met_condition": "2017-10-10T16:57:13.174Z",
- "actions": {
- "send_email": {
- "ack": {
- "timestamp": "2017-10-10T16:57:13.174Z",
- "state": "ackable"
- },
- "last_execution": {
- "timestamp": "2017-10-10T16:57:13.174Z",
- "successful": true
- },
- "last_successful_execution": {
- "timestamp": "2017-10-10T16:57:13.174Z",
- "successful": true
- }
- }
- }
- },
- "trigger_event": {
- "type": "manual",
- "triggered_time": "2017-10-10T16:57:13.174Z",
- "manual": {
- "schedule": {
- "scheduled_time": "2017-10-10T16:57:13.174Z"
- }
- }
- },
- "input": {
- "search": {
- "request": {
- "search_type": "dfs_query_then_fetch",
- "indices": [
- "<filebeat-{now/d}>"
- ],
- "types": [],
- "body": {
- "query": {
- "bool": {
- "must": [
- {
- "query_string": {
- "query": "NOT remote_ip:**IP ADDRESS**\\/24 OR NOT remote_ip:**IP ADDRESS**\\/24 OR NOT remote_ip:**IP ADDRESS**\\/16 OR NOT remote_ip:**IP ADDRESS**\\/24 OR NOT remote_ip:**IP ADDRESS**",
- "analyze_wildcard": true
- }
- },
- {
- "range": {
- "@timestamp": {
- "gte": "now-60s"
- }
- }
- }
- ],
- "must_not": []
- }
- },
- "size": 0,
- "aggs": {
- "2": {
- "terms": {
- "field": "remote_ip",
- "order": {
- "_count": "desc"
- }
- },
- "aggs": {
- "3": {
- "sum": {
- "field": "bytes"
- }
- }
- }
- }
- }
- }
- }
- }
- },
- "condition": {
- "compare": {
- "ctx.payload.aggregations.2.buckets.3.3.value": {
- "gt": "10000"
- }
- }
- },
- "result": {
- "execution_time": "2017-10-10T16:57:13.174Z",
- "execution_duration": 32,
- "input": {
- "type": "search",
- "status": "success",
- "payload": {
- "_shards": {
- "total": 5,
- "failed": 0,
- "successful": 5,
- "skipped": 0
- },
- "hits": {
- "hits": [],
- "total": 869,
- "max_score": 0
- },
- "took": 30,
- "timed_out": false,
- "aggregations": {
- "2": {
- "doc_count_error_upper_bound": 12,
- "sum_other_doc_count": 489,
- "buckets": [
- {
- "3": {
- "value": 432991
- },
- "doc_count": 57,
- "key": "**IP ADDRESS**"
- },
- {
- "3": {
- "value": 74919
- },
- "doc_count": 45,
- "key": "**IP ADDRESS**"
- },
- {
- "3": {
- "value": 169269
- },
- "doc_count": 45,
- "key": "**IP ADDRESS**"
- },
- {
- "3": {
- "value": 1562306
- },
- "doc_count": 42,
- "key": "**IP ADDRESS**"
- },
- {
- "3": {
- "value": 384091
- },
- "doc_count": 40,
- "key": "**IP ADDRESS**"
- },
- {
- "3": {
- "value": 258564
- },
- "doc_count": 38,
- "key": "**IP ADDRESS**"
- },
- {
- "3": {
- "value": 127922
- },
- "doc_count": 33,
- "key": "**IP ADDRESS**"
- },
- {
- "3": {
- "value": 292779
- },
- "doc_count": 33,
- "key": "**IP ADDRESS**"
- },
- {
- "3": {
- "value": 126337
- },
- "doc_count": 24,
- "key": "**IP ADDRESS**"
- },
- {
- "3": {
- "value": 118073
- },
- "doc_count": 23,
- "key": "**IP ADDRESS**"
- }
- ]
- }
- }
- },
- "search": {
- "request": {
- "search_type": "dfs_query_then_fetch",
- "indices": [
- "<filebeat-{now/d}>"
- ],
- "types": [],
- "body": {
- "query": {
- "bool": {
- "must": [
- {
- "query_string": {
- "query": "NOT remote_ip:**IP ADDRESS**\\/24 OR NOT remote_ip:**IP ADDRESS**\\/24 OR NOT remote_ip:**IP ADDRESS**\\/16 OR NOT remote_ip:**IP ADDRESS**\\/24 OR NOT remote_ip:**IP ADDRESS**",
- "analyze_wildcard": true
- }
- },
- {
- "range": {
- "@timestamp": {
- "gte": "now-60s"
- }
- }
- }
- ],
- "must_not": []
- }
- },
- "size": 0,
- "aggs": {
- "2": {
- "terms": {
- "field": "remote_ip",
- "order": {
- "_count": "desc"
- }
- },
- "aggs": {
- "3": {
- "sum": {
- "field": "bytes"
- }
- }
- }
- }
- }
- }
- }
- }
- },
- "condition": {
- "type": "compare",
- "status": "success",
- "met": true,
- "compare": {
- "resolved_values": {
- "ctx.payload.aggregations.2.buckets.3.3.value": 1562306
- }
- }
- },
- "actions": [
- {
- "id": "send_email",
- "type": "email",
- "status": "simulated",
- "email": {
- "message": {
- "id": "_inlined__2ea51f76-2808-4d82-901c-102024563d9c-2017-10-10T16:57:13.174Z",
- "sent_date": "2017-10-10T16:57:13.206Z",
- "to": [
- "**EMAIL ADDRESS**"
- ],
- "subject": "Watcher Test Alert",
- "body": {
- "text": "The IP [**IP ADDRESS** ] spiked useage with [1562306.0 ]"
- }
- }
- }
- }
- ]
- },
- "messages": []
- }
Add Comment
Please, Sign In to add comment