Skip to content

Commit

Permalink
Merge pull request #350 from DFE-Digital/alert-docs
Browse files Browse the repository at this point in the history
Improve docs on logit elastalert
  • Loading branch information
neillturner authored Jan 15, 2025
2 parents a0c18ed + 554f9c0 commit 0f09517
Showing 1 changed file with 9 additions and 1 deletion.
10 changes: 9 additions & 1 deletion documentation/logit-io.md
Original file line number Diff line number Diff line change
Expand Up @@ -51,10 +51,18 @@ To create a new stack:
## Monitoring and Alerting

We have enabled Logit stack alerts and notification (elastalert).
Each stack has a monitor for too many logs per hour, and no logs in 30 minutes.

Each stack has a monitor for
- too many logs per hour
- no logs in 30 minutes
- email addresses in the logs

When triggered, an email alert will be sent to the TS Infra team email address, and we should investigate why there are too many or missing logs.

It will re-alert every 3 hours until any issue is resolved.

See [Elastart docs](https://elastalert.readthedocs.io/) for info on writing alerts.

## Logstash inputs
Filebeat sends logs to logstash as json so they can be decoded to create fields in ElasticSearch and query them with Kibana.

Expand Down

0 comments on commit 0f09517

Please sign in to comment.