Last active
May 23, 2021 03:41
-
-
Save nitesh8860/29f485001396a7a69f619d146b4aa3c4 to your computer and use it in GitHub Desktop.
this usecase is related to app logs where if some message fails trying multiple times, the script will identify that message and then collect all related logs to that error and send it to email.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| ''' | |
| example data: | |
| name: someText aFewMoreRandomThings aggregate_id: someNumber | |
| if this error is found, the script will search for all related logs to this aggregate_id and the text Retries exceeded (RMQ specific). | |
| script will then collect all this data and send it to email | |
| error type: {} | |
| aggregateid: {}\n | |
| mq deadfinal log: \n{} | |
| related log : \n{} | |
| ''' | |
| from elasticsearch import Elasticsearch | |
| import re | |
| import smtplib, ssl | |
| from datetime import datetime | |
| #GLOBAL VARS | |
| filebeat_index="filebeat-"+datetime.now().strftime("%Y.%m.*") | |
| documentnos=20 | |
| queue="" | |
| invoiceid="" | |
| print("\n\n"+str(datetime.now())+" , searching the index: "+filebeat_index+" , starting search -----") | |
| print(filebeat_index) | |
| #SMTP VARS | |
| port = 25 # For starttls | |
| smtp_server = "xxxxx" | |
| sender_email = "xxxxx" | |
| receiver_email = ['xxxxx','xxxxx','xxxxxx'] | |
| password='xxxxx' | |
| es = Elasticsearch() | |
| res = es.search( | |
| index=filebeat_index, | |
| size=documentnos, | |
| body= | |
| { | |
| "query": { | |
| "bool": { | |
| "must": [ | |
| { | |
| "match": { | |
| "source": "/var/xxxxx/xxxxx/log/xxxxx.log" | |
| } | |
| } | |
| ], | |
| "filter": { | |
| "range": { | |
| "@timestamp": { | |
| "gte": "now-15m" | |
| } | |
| } | |
| } | |
| } | |
| } | |
| } | |
| ) | |
| print("%d documents found" % res['hits']['total']) | |
| documentnos=int(res['hits']['total']) | |
| print("\n*************searching for docs to mail*****************\n") | |
| for doc in res['hits']['hits']: | |
| print("\n*************searching for docs to mail*****************\n") | |
| print(doc) | |
| for doc in res['hits']['hits']: | |
| try: | |
| regd=re.compile(r'name\":\"([\w.]+)\".*aggregate_id\":(\d+)') | |
| queue=regd.search("%s) %s" % (doc['_id'], doc['_source']['message'])).group(1) | |
| key=regd.search("%s) %s" % (doc['_id'], doc['_source']['message'])).group(2) | |
| except : | |
| print("no match with name and aggregate id ") | |
| pass | |
| print("\n@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@Found a Doc@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@\n") | |
| print(queue) | |
| print(key) | |
| res1 = es.search( | |
| index=filebeat_index, | |
| size=documentnos, | |
| body= | |
| { | |
| "query":{ | |
| "bool":{ | |
| "must":[ | |
| #{"match": {"message":queue}}, | |
| {"match": {"message":key}} | |
| ,{"match": {"message":"Retries exceeded"}} | |
| ] | |
| } | |
| } | |
| } | |
| ) | |
| print("%d documents found" % res1['hits']['total']) | |
| for doc in res1['hits']['hits']: | |
| print("starting search for "+str(doc)) | |
| print("%s) %s" % (doc['_id'], doc['_source']['message'])) | |
| error=("%s) %s" % (doc['_id'], doc['_source']['message'])) | |
| mq=res['hits']['hits'][0]['_source']['message'] | |
| print("sending message") | |
| message = """\ | |
| \n | |
| Subject: ALERT | |
| You have got below error in the system: | |
| error type: {} | |
| aggregateid: {}\n | |
| mq deadfinal log: \n{} | |
| related log : \n{} | |
| """.format(queue,key,mq,error) | |
| server = smtplib.SMTP(smtp_server, port) | |
| server.starttls | |
| server.login(sender_email, password) | |
| server.sendmail(sender_email, receiver_email, message) | |
| server.quit() | |
| print("message sent, looking for more docs") |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment