elastalert icon indicating copy to clipboard operation
elastalert copied to clipboard

Added elastalert_status index timestamping

Open Qmando opened this issue 7 years ago • 9 comments

Allow you to set writeback_index: elastalert-status-%Y.%m etc.

Also a minor fix that would causing duplicate indices from format_index.

Fixes #684

Qmando avatar Mar 10 '17 22:03 Qmando

Regardingcreate_index

I guess create_index effectively becomes obsolete if you are using this feature. Unless you are trying to copy data from an old index. That should be reflected in the documentation.

Do you mean bootstrapping from a non-timestamped index? In that case, no. I'll probably add a section on the documentation on how to use create-index to copy over some data and switch. You'd have to manually input elastalert_status-2017.03 or whatever, which would be very prone to human error, so maybe I'll add that functionality into the script.

Qmando avatar Mar 13 '17 22:03 Qmando

Hello there, do you think that this PR can be merged now?

Thanks!

alesnav avatar Jun 16 '17 07:06 alesnav

I'm also very interested in this. Anything I can help with to get this moving?

AndreLouisCaron avatar Jul 10 '17 15:07 AndreLouisCaron

If someone wants to test this branch and report back any issues, that would be awesome.

I'll reprioritize getting this out, I think I still need to add documentation, do some more thorough documentation, and add a way to migrate from an old fixed index name seamlessly.

Qmando avatar Jul 10 '17 21:07 Qmando

Hello. Is this going to be merged anytime soon?. I am very interested on this.

angocor avatar Feb 15 '18 15:02 angocor

also interested in this feature, otherwise its simple enough to have an out of band process that runs to create a new daily/whatever index and then writeback_index references an alias

donwalrus avatar Mar 01 '18 06:03 donwalrus

This is something that would be very useful in our environment so I'm very interested if this could be implemented. Being able to run curator against the indexes for a certain time span would be extremely good.

Since it's gone a year since the last comments - are there any plans of getting this merged?

TIA

swedishmike avatar Mar 26 '19 14:03 swedishmike

@Qmando , any update on this?

gartemiev avatar Aug 26 '19 13:08 gartemiev

I'd to see this merged.

vtdat avatar Aug 24 '20 08:08 vtdat