Skip to content

Instantly share code, notes, and snippets.

@nitesh8860
Last active May 23, 2021 03:41
Show Gist options
  • Select an option

  • Save nitesh8860/29f485001396a7a69f619d146b4aa3c4 to your computer and use it in GitHub Desktop.

Select an option

Save nitesh8860/29f485001396a7a69f619d146b4aa3c4 to your computer and use it in GitHub Desktop.
this usecase is related to app logs where if some message fails trying multiple times, the script will identify that message and then collect all related logs to that error and send it to email.
'''
example data:
name: someText aFewMoreRandomThings aggregate_id: someNumber
if this error is found, the script will search for all related logs to this aggregate_id and the text Retries exceeded (RMQ specific).
script will then collect all this data and send it to email
error type: {}
aggregateid: {}\n
mq deadfinal log: \n{}
related log : \n{}
'''
from elasticsearch import Elasticsearch
import re
import smtplib, ssl
from datetime import datetime
#GLOBAL VARS
filebeat_index="filebeat-"+datetime.now().strftime("%Y.%m.*")
documentnos=20
queue=""
invoiceid=""
print("\n\n"+str(datetime.now())+" , searching the index: "+filebeat_index+" , starting search -----")
print(filebeat_index)
#SMTP VARS
port = 25 # For starttls
smtp_server = "xxxxx"
sender_email = "xxxxx"
receiver_email = ['xxxxx','xxxxx','xxxxxx']
password='xxxxx'
es = Elasticsearch()
res = es.search(
index=filebeat_index,
size=documentnos,
body=
{
"query": {
"bool": {
"must": [
{
"match": {
"source": "/var/xxxxx/xxxxx/log/xxxxx.log"
}
}
],
"filter": {
"range": {
"@timestamp": {
"gte": "now-15m"
}
}
}
}
}
}
)
print("%d documents found" % res['hits']['total'])
documentnos=int(res['hits']['total'])
print("\n*************searching for docs to mail*****************\n")
for doc in res['hits']['hits']:
print("\n*************searching for docs to mail*****************\n")
print(doc)
for doc in res['hits']['hits']:
try:
regd=re.compile(r'name\":\"([\w.]+)\".*aggregate_id\":(\d+)')
queue=regd.search("%s) %s" % (doc['_id'], doc['_source']['message'])).group(1)
key=regd.search("%s) %s" % (doc['_id'], doc['_source']['message'])).group(2)
except :
print("no match with name and aggregate id ")
pass
print("\n@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@Found a Doc@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@\n")
print(queue)
print(key)
res1 = es.search(
index=filebeat_index,
size=documentnos,
body=
{
"query":{
"bool":{
"must":[
#{"match": {"message":queue}},
{"match": {"message":key}}
,{"match": {"message":"Retries exceeded"}}
]
}
}
}
)
print("%d documents found" % res1['hits']['total'])
for doc in res1['hits']['hits']:
print("starting search for "+str(doc))
print("%s) %s" % (doc['_id'], doc['_source']['message']))
error=("%s) %s" % (doc['_id'], doc['_source']['message']))
mq=res['hits']['hits'][0]['_source']['message']
print("sending message")
message = """\
\n
Subject: ALERT
You have got below error in the system:
error type: {}
aggregateid: {}\n
mq deadfinal log: \n{}
related log : \n{}
""".format(queue,key,mq,error)
server = smtplib.SMTP(smtp_server, port)
server.starttls
server.login(sender_email, password)
server.sendmail(sender_email, receiver_email, message)
server.quit()
print("message sent, looking for more docs")
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment