We have a straightforward Logstash->Elasticsearch stack, getting logs data from various applications and storing everything into well, Elasticsearch.
We also use Kibana to search for the relevant informations
I would like to be able to trigger alerts on some specific logs which can be searched at the moment with Kibana running on top of Elasticsearch.
I was thinking I could leverage Sensu to do this, but I’m not sure how and if it’s a good idea actually.
A naive approach would be to query Elasticsearch to get the relevant data for the past X minutes but something better would be to find a way to do the queries and get the results which have been produced since the last time the check ran. How would I store this information then?
Is there anybody doing something like this with Sensu?