Slide 49
Slide 49 text
49
Alerting設定方法(3/6)
監視対象データをクエリベースで指定する場合は、[Define using extraction query]を利用する。
{
"size": 0,
"query": {
"bool": {
"must": [
{
"match_all": {
"boost": 1
}
},
{
"match_phrase": {
“trusted_ip": {
"query": "false",
"slop": 0,
"zero_terms_query": "NONE",
"boost": 1
}
}
},
{
"match_phrase": {
"eventType": {
"query": "AwsConsoleSignIn",
"slop": 0,
"zero_terms_query": "NONE",
"boost": 1
}
}
},
{
"range": {
"cloudwatch_logs.ingestion_time": {
"from": "now-5m",
"to": "now",
"include_lower": true,
"include_upper": true,
"format": "epoch_millis",
"boost": 1
}
}
}
],
"adjust_pure_negative": true,
"boost": 1
}
}
}