Skip to content

Is there a way to make that work with ES 7.5 ?  #150

@romankor

Description

@romankor
01:49:00.977Z  INFO elastalert-server: Server:  Server started
01:49:01.822Z ERROR elastalert-server:
    ProcessController:  Traceback (most recent call last):
      File "/usr/lib/python2.7/runpy.py", line 174, in _run_module_as_main
        "__main__", fname, loader, pkg_name)
01:49:01.824Z ERROR elastalert-server:
    ProcessController:    File "/usr/lib/python2.7/runpy.py", line 72, in _run_code
        exec code in run_globals
      File "/opt/elastalert/elastalert/elastalert.py", line 1929, in <module>
        sys.exit(main(sys.argv[1:]))
      File "/opt/elastalert/elastalert/elastalert.py", line 1925, in main
        client.start()
      File "/opt/elastalert/elastalert/elastalert.py", line 1106, in start
01:49:01.826Z ERROR elastalert-server:
    ProcessController:      self.run_all_rules()
01:49:01.827Z ERROR elastalert-server:
    ProcessController:    File "/opt/elastalert/elastalert/elastalert.py", line 1158, in run_all_rules
01:49:01.829Z ERROR elastalert-server:
    ProcessController:      self.send_pending_alerts()
01:49:01.830Z ERROR elastalert-server:
    ProcessController:    File "/opt/elastalert/elastalert/elastalert.py", line 1534, in send_pending_alerts
01:49:01.831Z ERROR elastalert-server:
    ProcessController:      pending_alerts = self.find_recent_pending_alerts(self.alert_time_limit)
      File "/opt/elastalert/elastalert/elastalert.py", line 1526, in find_recent_pending_alerts
01:49:01.832Z ERROR elastalert-server:
    ProcessController:      size=1000)
      File "/usr/lib/python2.7/site-packages/elasticsearch-7.0.1-py2.7.egg/elasticsearch/client/utils.py", line 84, in _wrapped
01:49:01.833Z ERROR elastalert-server:
    ProcessController:      return func(*args, params=params, **kwargs)
01:49:01.834Z ERROR elastalert-server:
    ProcessController:  TypeError: search() got an unexpected keyword argument 'doc_type'

I am running that in kubernetes:

Image : bitsensor/elastalert :2.0.1

Startup line : command: ['sh', '-c', 'apk add py2-pip && pip install elasticsearch==6.3.1 && npm start']

I am getting it right you guys not want to develop that any more ? i see PR;s not being touched for half a year ...

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions