Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- {
- "watch_id": "_inlined_",
- "state": "failed",
- "status": {
- "state": {
- "active": true,
- "timestamp": "2017-11-24T09:09:37.648Z"
- },
- "actions": {
- "notify-pagerduty": {
- "ack": {
- "timestamp": "2017-11-24T09:09:37.648Z",
- "state": "awaits_successful_execution"
- }
- }
- }
- },
- "trigger_event": {
- "type": "manual",
- "triggered_time": "2017-11-24T09:09:37.648Z",
- "manual": {
- "schedule": {
- "scheduled_time": "2017-11-24T09:09:37.648Z"
- }
- }
- },
- "input": {
- "search": {
- "request": {
- "search_type": "query_then_fetch",
- "indices": [
- "<logstash-infra-{now/d}>"
- ],
- "types": [],
- "body": {
- "size": 0,
- "query": {
- "bool": {
- "must": [
- {
- "query_string": {
- "query": "system.auth.ssh.event: Failed OR Invalid"
- }
- },
- {
- "range": {
- "@timestamp": {
- "gte": "{{ctx.trigger.triggered_time}}||-1m"
- }
- }
- }
- ]
- }
- },
- "aggs": {
- "user": {
- "terms": {
- "field": "system.auth.user"
- }
- }
- }
- }
- }
- }
- },
- "condition": {
- "compare": {
- "ctx.payload.aggregations.user.buckets.0.doc_count": {
- "gte": 1
- }
- }
- },
- "metadata": {
- "name": "SSH FAiled again..."
- },
- "result": {
- "execution_time": "2017-11-24T09:09:37.648Z",
- "execution_duration": 2,
- "input": {
- "type": "search",
- "status": "success",
- "payload": {
- "_shards": {
- "total": 5,
- "failed": 0,
- "successful": 5,
- "skipped": 0
- },
- "hits": {
- "hits": [],
- "total": 0,
- "max_score": 0
- },
- "took": 1,
- "timed_out": false,
- "aggregations": {
- "user": {
- "doc_count_error_upper_bound": 0,
- "sum_other_doc_count": 0,
- "buckets": []
- }
- }
- },
- "search": {
- "request": {
- "search_type": "query_then_fetch",
- "indices": [
- "<logstash-infra-{now/d}>"
- ],
- "types": [],
- "body": {
- "size": 0,
- "query": {
- "bool": {
- "must": [
- {
- "query_string": {
- "query": "system.auth.ssh.event: Failed OR Invalid"
- }
- },
- {
- "range": {
- "@timestamp": {
- "gte": "2017-11-24T09:09:37.648Z||-1m"
- }
- }
- }
- ]
- }
- },
- "aggs": {
- "user": {
- "terms": {
- "field": "system.auth.user"
- }
- }
- }
- }
- }
- }
- },
- "actions": []
- },
- "exception": {
- "type": "index_out_of_bounds_exception",
- "reason": "Index: 0, Size: 0"
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement