Skip to content

Is there a way to make that work with ES 7.5 ?  #150

@romankor

Description

@romankor
01:49:00.977Z  INFO elastalert-server: Server:  Server started
01:49:01.822Z ERROR elastalert-server:
    ProcessController:  Traceback (most recent call last):
      File "/usr/lib/python2.7/runpy.py", line 174, in _run_module_as_main
        "__main__", fname, loader, pkg_name)
01:49:01.824Z ERROR elastalert-server:
    ProcessController:    File "/usr/lib/python2.7/runpy.py", line 72, in _run_code
        exec code in run_globals
      File "/opt/elastalert/elastalert/elastalert.py", line 1929, in <module>
        sys.exit(main(sys.argv[1:]))
      File "/opt/elastalert/elastalert/elastalert.py", line 1925, in main
        client.start()
      File "/opt/elastalert/elastalert/elastalert.py", line 1106, in start
01:49:01.826Z ERROR elastalert-server:
    ProcessController:      self.run_all_rules()
01:49:01.827Z ERROR elastalert-server:
    ProcessController:    File "/opt/elastalert/elastalert/elastalert.py", line 1158, in run_all_rules
01:49:01.829Z ERROR elastalert-server:
    ProcessController:      self.send_pending_alerts()
01:49:01.830Z ERROR elastalert-server:
    ProcessController:    File "/opt/elastalert/elastalert/elastalert.py", line 1534, in send_pending_alerts
01:49:01.831Z ERROR elastalert-server:
    ProcessController:      pending_alerts = self.find_recent_pending_alerts(self.alert_time_limit)
      File "/opt/elastalert/elastalert/elastalert.py", line 1526, in find_recent_pending_alerts
01:49:01.832Z ERROR elastalert-server:
    ProcessController:      size=1000)
      File "/usr/lib/python2.7/site-packages/elasticsearch-7.0.1-py2.7.egg/elasticsearch/client/utils.py", line 84, in _wrapped
01:49:01.833Z ERROR elastalert-server:
    ProcessController:      return func(*args, params=params, **kwargs)
01:49:01.834Z ERROR elastalert-server:
    ProcessController:  TypeError: search() got an unexpected keyword argument 'doc_type'

I am running that in kubernetes:

Image : bitsensor/elastalert :2.0.1

Startup line : command: ['sh', '-c', 'apk add py2-pip && pip install elasticsearch==6.3.1 && npm start']

I am getting it right you guys not want to develop that any more ? i see PR;s not being touched for half a year ...

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions