Book Image

Learning Elasticsearch

By : Abhishek Andhavarapu
Book Image

Learning Elasticsearch

By: Abhishek Andhavarapu

Overview of this book

Elasticsearch is a modern, fast, distributed, scalable, fault tolerant, and open source search and analytics engine. You can use Elasticsearch for small or large applications with billions of documents. It is built to scale horizontally and can handle both structured and unstructured data. Packed with easy-to- follow examples, this book will ensure you will have a firm understanding of the basics of Elasticsearch and know how to utilize its capabilities efficiently. You will install and set up Elasticsearch and Kibana, and handle documents using the Distributed Document Store. You will see how to query, search, and index your data, and perform aggregation-based analytics with ease. You will see how to use Kibana to explore and visualize your data. Further on, you will learn to handle document relationships, work with geospatial data, and much more, with this easy-to-follow guide. Finally, you will see how you can set up and scale your Elasticsearch clusters in production environments.
Table of Contents (11 chapters)
10
Exploring Elastic Stack (Elastic Cloud, Security, Graph, and Alerting)

Alerting

Just like Graph, alerting is a part of X-Pack Gold and Platinum subscription. Alerting was formerly known as . You can define watchers on cluster events and existing indexes. Watcher can be configured to be executed on schedule. Elasticsearch alerting is very flexible, and the input can be the response to an HTTP request or a query on existing Elasticsearch index. A watch is triggered if the input matches a predefined condition. For example, the input can be the cluster status and condition is "if the cluster status is red". When a condition is triggered, you can define what action has to be taken. An action can be sending an e-mail, indexing a document, sending a slack message, and so on.

For an e-commerce store, let's define a watcher to alert if less than five orders have been placed within the last 30 minutes. The action we will take when the condition...