最近项目中日志不是实时进行索引,elastalert是默认进行实时预警,无法达到合理的预警效果,翻看elastalert技术文档发现还有这么个query_delay参数,完美解决问题。
query_delay参数描述如下:
This option will cause ElastAlert to subtract a time delta from every query, causing the rule to run with a delay. This is useful if the data is Elasticsearch doesn’t get indexed immediately. (Optional, time)