Skip to content

Docker images compatibility #178

Description

@naretto

Hi,

Is there a compatibility list of the docker images between Elastic Search and Elast Alert?

For example: Elastic Search docker 7.8.0 is compatible with ElastAlert docker x.x.x and so on.

I have been trying to get Elast Alert working for the past few days, but keep getting errors when it tries to query data, Based on what I have read on what worked for other people, it comes down to incompatible versions being used.

Example:
Error "No mapping found for [@timestamp] in order to sort on". Even making sure the mapping is there and correct by checking on http://localhost:9200/elastalert*/_mapping

Also, is this project still active? It seems last commit and docker image are over 1 year old and issues are not being replied or worked on.

Thank you.

Activity

  1. nsano-rururu commented on Jul 14, 2020

    @nsano-rururu

    Is there a compatibility list of the docker images between Elastic Search and Elast Alert?

    If you want to use the latest ElastAlert, I recommend using johnsusek/elastalert-server, which is a fork of Bitsensor.
    Customizations, bug fixes, ElastAlert 0.2.4 support, library updates, etc.

    johnsusek/elastalert-server (DockerHub)
    https://hub.docker.com/r/johnsusek/elastalert-server
    johnsusek/elastalert-server (GitHub)
    https://github.com/johnsusek/elastalert-server

    Supports Elasticsearch 7.x from ElastAlert 0.2.0b2

    Docker image name tag ElastAlert Elasticsearch 7 Support Remarks
    bitsensor/elastalert 2.0.1 0.1.39 ×
    bitsensor/elastalert lastet 0.1.39 ×
    bitsensor/elastalert 3.0.0-beta.0 0.2.0b2 〇
    bitsensor/elastalert 3.0.0-beta.1 0.2.0b2 〇
    servercentral/elastalert latest 0.2.1 〇 bitsensor/elastalert fork
    Customize
    bug fix
    daichi703n/elastalert 0.2.1-dev2 0.2.1 〇 servercentral/elastalert fork
    Customize
    johnsusek/elastalert-server 1592081541 0.2.4 〇 servercentral/elastalert fork
    Customize
    Library Update
    bug fix
  2. nsano-rururu commented on Jul 14, 2020

    @nsano-rururu
  3. tracylucky commented on Aug 3, 2021

    @tracylucky

    Hi @nsano-rururu
    I am try to run container by docker run , but got this error, could you please help to take a look? I used this fork https://github.com/johnsusek/elastalert-server, I'd like to submit an issue in the git url, no issues tab, so I created her

    ProcessController: ERROR:apscheduler.executors.default:Job "Internal: Handle Pending Alerts (trigger: interval[0:00:05], next run at: 2021-08-03 03:22:39 UTC)" raised an exception
    Traceback (most recent call last):
    File "/home/node/.local/lib/python3.9/site-packages/elasticsearch/serializer.py", line 77, in loads
    deserializer = self.serializers[mimetype]
    KeyError: 'text/html'

    During handling of the above exception, another exception occurred:
    
    Traceback (most recent call last):
      File "/home/node/.local/lib/python3.9/site-packages/apscheduler/executors/base.py", line 125, in run_job
        retval = job.func(*job.args, **job.kwargs)
      File "/opt/elastalert/elastalert/elastalert.py", line 1288, in handle_pending_alerts
        self.send_pending_alerts()
      File "/opt/elastalert/elastalert/elastalert.py", line 1716, in send_pending_alerts
        pending_alerts = self.find_recent_pending_alerts(self.alert_time_limit)
      File "/opt/elastalert/elastalert/elastalert.py", line 1698, in find_recent_pending_alerts
        if self.writeback_es.is_atleastfive():
      File "/opt/elastalert/elastalert/__init__.py", line 63, in is_atleastfive
        return int(self.es_version.split(".")[0]) >= 5
      File "/opt/elastalert/elastalert/__init__.py", line 51, in es_version
        self._es_version = self.info()['version']['number']
      File "/home/node/.local/lib/python3.9/site-packages/elasticsearch/client/utils.py", line 84, in _wrapped
        return func(*args, params=params, **kwargs)
      File "/home/node/.local/lib/python3.9/site-packages/elasticsearch/client/__init__.py", line 259, in info
        return self.transport.perform_request("GET", "/", params=params)
      File "/home/node/.local/lib/python3.9/site-packages/elasticsearch/transport.py", line 349, in perform_request
        data = self.deserializer.loads(data, headers_response.get('content-type'))
      File "/home/node/.local/lib/python3.9/site-packages/elasticsearch/serializer.py", line 79, in loads
        raise SerializationError('Unknown mimetype, unable to deserialize: %s' % mimetype)
    elasticsearch.exceptions.SerializationError: Unknown mimetype, unable to deserialize: text/html
    
  4. nsano-rururu commented on Aug 3, 2021

    @nsano-rururu

    @tracylucky

    Since the error is on the python side, is it a problem with elastalert2? ..
    Why don't you write environmental information? You'll need to interact with it several times. What is the version of elasticsearch? .. For 5 instead of 6 or 7, you need to run pip uninstall elasitcsearch and elasticsearch>= 5.0.0,<6.0.0.

  5. nsano-rururu commented on Aug 3, 2021

    @nsano-rururu

    @tracylucky

    Please write in the following issue. I don't have full permissions on the repository so I can't enable the johnsusek / elastalert-server issue.
    https://github.com/johnsusek/praeco

  6. nsano-rururu commented on Aug 3, 2021

    @nsano-rururu

    @tracylucky

    We have not confirmed the operation with elasticsearch 5 and 6.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions