请先看上一篇《Elastalert Spike 配置说明》
top_count_keys: ["ip","loginname"]
这个配置的意思是,按照count顺序把前5(默认)个ip字段和loginname加到邮件里。下面就是邮件报警的内容格式:
tanxiaolongspiketest
An abnormal number (2045) of events occurred around 2016-08-24 20:48 CST.
Preceding that time, there were only 0 events within 0:02:00
ip.raw:
220.180.37.169: 21
114.96.212.53: 20
114.96.223.71: 17
60.168.62.2: 16
220.180.32.225: 15
loginname.raw:
unknown: 750
%{[data][4]}: 19
13980365780: 6
13514081319: 6
如果你想控制个数的话,可以通过
top_count_number
来进行控制。