Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Shell script and powershell connector for watcher alerts #105381

Open
marcelvarallo-leidos opened this issue Jul 13, 2021 · 6 comments
Open

Shell script and powershell connector for watcher alerts #105381

marcelvarallo-leidos opened this issue Jul 13, 2021 · 6 comments
Labels
connectivity Issues relating to connectivity between Kibana and external services discuss enhancement New value added to drive a business result estimate:needs-research Estimated as too large and requires research to break down into workable issues Feature:Actions/ConnectorTypes Issues related to specific Connector Types on the Actions Framework Team:ResponseOps Label for the ResponseOps team (formerly the Cases and Alerting teams)

Comments

@marcelvarallo-leidos
Copy link

Describe the feature:
A powershell and Shell/bash script connector for watcher alerts

Describe a specific use case for the feature:
In the event of certain alerts, trigger a shell script or powershell command parsing in detail from the alert.

I currently have an intermittent issue with one of my servers and I'd like to run a diagnostic script when it happens but it disappears before I notice and can run the script.

@botelastic botelastic bot added the needs-team Issues missing a team label label Jul 13, 2021
@cjcenizal
Copy link
Contributor

@marcelvarallo-leidos By "connector" do mean a new type of Watcher action? If so, then I believe you're requesting an Elasticsearch enhancement.

@marcelvarallo-leidos
Copy link
Author

Apologies, I use several versions of Elasticsearch and it appears I got a little confused. In the Alerts and Actions section, there's a tab to create new Connectors and contains items like webhook, email, jira etc. That's the area I was thinking of. But a watcher action would be good too :)

@marcelvarallo-leidos
Copy link
Author

If we had this feature, I could create a diagnostic index and then use this alert action to (for example) call nslookup/tracert/whatever diagnostic tool needs to be run when the Alert happens and output the response to a file which filebeat scoops into that index so I can check what was happening elsewhere when this happened.

@timroes timroes added the Team:ResponseOps Label for the ResponseOps team (formerly the Cases and Alerting teams) label Jul 21, 2021
@elasticmachine
Copy link
Contributor

Pinging @elastic/kibana-alerting-services (Team:Alerting Services)

@botelastic botelastic bot removed the needs-team Issues missing a team label label Jul 21, 2021
@gmmorris gmmorris added Feature:Actions/ConnectorTypes Issues related to specific Connector Types on the Actions Framework loe:needs-research This issue requires some research before it can be worked on or estimated labels Jul 28, 2021
@mikecote
Copy link
Contributor

mikecote commented Aug 4, 2021

cc @arisonl

@gmmorris gmmorris added connectivity Issues relating to connectivity between Kibana and external services enhancement New value added to drive a business result estimate:needs-research Estimated as too large and requires research to break down into workable issues labels Aug 16, 2021
@gmmorris gmmorris removed the loe:needs-research This issue requires some research before it can be worked on or estimated label Sep 2, 2021
@kobelb kobelb added the needs-team Issues missing a team label label Jan 31, 2022
@botelastic botelastic bot removed the needs-team Issues missing a team label label Jan 31, 2022
@Erikg346
Copy link

This would be so helpful +1
As mentioned here: https://discuss.elastic.co/t/how-to-run-powershell-scripts-with-elastic/357224?u=erikg

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
connectivity Issues relating to connectivity between Kibana and external services discuss enhancement New value added to drive a business result estimate:needs-research Estimated as too large and requires research to break down into workable issues Feature:Actions/ConnectorTypes Issues related to specific Connector Types on the Actions Framework Team:ResponseOps Label for the ResponseOps team (formerly the Cases and Alerting teams)
Projects
No open projects
Development

No branches or pull requests

8 participants