我想为 EFK 堆栈实施警报,该堆栈部署在 Openshift 源中。为了实现警报,我使用了 Elastalert。我使用了 krizsan/elastalert-docker docker 镜像。
oc run elastalertcore --image=172.30.1.1:5000/logging/elastalert-core --port=3344 --expose
这将成功运行 elastalert 实例,但在日志中我得到
Container timezone set to: Europe/Stockholm
ntpd: can't set priority: Permission denied
reset adjtime failed: Operation not permitted
creating new /var/db/ntpd.drift
adjtimex failed: Operation not permitted
dispatch_imsg in main: pipe closed
Lost child: child exited
Terminating
Waiting for Elasticsearch...
Waiting for Elasticsearch...
Waiting for Elasticsearch...
Waiting for Elasticsearch...
我给了环境变量
ELASTICSEARCH_HOST =logging-es
Elastalert 无法连接到开放班次原点的弹性搜索。任何帮助表示赞赏..