alert.json 1.6 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061
  1. {
  2. "name": "test",
  3. "type": "monitor",
  4. "monitor_type": "query_level_monitor",
  5. "enabled": true,
  6. "schedule": {
  7. "period": {
  8. "unit": "MINUTES",
  9. "interval": 1
  10. }
  11. },
  12. "inputs": [
  13. {
  14. "search": {
  15. "indices": [
  16. "audit-trails-index"
  17. ],
  18. "query": {
  19. "size": 0,
  20. "aggregations": {},
  21. "query": {
  22. "bool": {
  23. "filter": [
  24. {
  25. "range": {
  26. "@timestamp": {
  27. "gte": "{{period_end}}||-1h",
  28. "lte": "{{period_end}}",
  29. "format": "epoch_millis"
  30. }
  31. }
  32. },
  33. {
  34. "match_phrase": {
  35. "event.action": "yandex.cloud.audit.iam.CreateAccessKey"
  36. }
  37. }
  38. ]
  39. }
  40. }
  41. }
  42. }
  43. }
  44. ],
  45. "triggers": [
  46. {
  47. "query_level_trigger": {
  48. "id": "4-GknIIBRFYBrLZDkWVh",
  49. "name": "test",
  50. "severity": "1",
  51. "condition": {
  52. "script": {
  53. "source": "ctx.results[0].hits.total.value > 0",
  54. "lang": "painless"
  55. }
  56. }
  57. }
  58. }
  59. ]
  60. }