Skip to content

Instantly share code, notes, and snippets.

@dvas0004 dvas0004/alerting.xml
Last active Apr 11, 2019

Embed
What would you like to do?
Apache NiFi template for elasticsearch alerting : https://blog.davidvassallo.me/2019/04/11/is-it-elastalert-no-it-is-nifi/
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<template encoding-version="1.2">
<description></description>
<groupId>0b75361c-016a-1000-e901-df6077c56bf0</groupId>
<name>Alerting</name>
<snippet>
<connections>
<id>37ad2546-e691-3c83-0000-000000000000</id>
<parentGroupId>673af2b8-8391-3580-0000-000000000000</parentGroupId>
<backPressureDataSizeThreshold>1 GB</backPressureDataSizeThreshold>
<backPressureObjectThreshold>10000</backPressureObjectThreshold>
<destination>
<groupId>673af2b8-8391-3580-0000-000000000000</groupId>
<id>b2cef930-dcbc-38f5-0000-000000000000</id>
<type>PROCESSOR</type>
</destination>
<flowFileExpiration>0 sec</flowFileExpiration>
<labelIndex>1</labelIndex>
<name></name>
<selectedRelationships>success</selectedRelationships>
<source>
<groupId>673af2b8-8391-3580-0000-000000000000</groupId>
<id>9002185e-06dd-367a-0000-000000000000</id>
<type>PROCESSOR</type>
</source>
<zIndex>0</zIndex>
</connections>
<connections>
<id>576054d1-8cbf-320e-0000-000000000000</id>
<parentGroupId>673af2b8-8391-3580-0000-000000000000</parentGroupId>
<backPressureDataSizeThreshold>1 GB</backPressureDataSizeThreshold>
<backPressureObjectThreshold>10000</backPressureObjectThreshold>
<destination>
<groupId>673af2b8-8391-3580-0000-000000000000</groupId>
<id>ab213d84-4a44-36a0-0000-000000000000</id>
<type>PROCESSOR</type>
</destination>
<flowFileExpiration>0 sec</flowFileExpiration>
<labelIndex>1</labelIndex>
<name></name>
<selectedRelationships>matched</selectedRelationships>
<source>
<groupId>673af2b8-8391-3580-0000-000000000000</groupId>
<id>ef2824c1-6117-382d-0000-000000000000</id>
<type>PROCESSOR</type>
</source>
<zIndex>0</zIndex>
</connections>
<connections>
<id>76448153-4531-39fe-0000-000000000000</id>
<parentGroupId>673af2b8-8391-3580-0000-000000000000</parentGroupId>
<backPressureDataSizeThreshold>1 GB</backPressureDataSizeThreshold>
<backPressureObjectThreshold>10000</backPressureObjectThreshold>
<destination>
<groupId>673af2b8-8391-3580-0000-000000000000</groupId>
<id>834fb412-0d0e-3dca-0000-000000000000</id>
<type>PROCESSOR</type>
</destination>
<flowFileExpiration>0 sec</flowFileExpiration>
<labelIndex>1</labelIndex>
<name></name>
<selectedRelationships>matched</selectedRelationships>
<source>
<groupId>673af2b8-8391-3580-0000-000000000000</groupId>
<id>ab213d84-4a44-36a0-0000-000000000000</id>
<type>PROCESSOR</type>
</source>
<zIndex>0</zIndex>
</connections>
<connections>
<id>81545f67-ca28-3275-0000-000000000000</id>
<parentGroupId>673af2b8-8391-3580-0000-000000000000</parentGroupId>
<backPressureDataSizeThreshold>1 GB</backPressureDataSizeThreshold>
<backPressureObjectThreshold>10000</backPressureObjectThreshold>
<destination>
<groupId>673af2b8-8391-3580-0000-000000000000</groupId>
<id>7703dd54-5f75-3b30-0000-000000000000</id>
<type>PROCESSOR</type>
</destination>
<flowFileExpiration>0 sec</flowFileExpiration>
<labelIndex>1</labelIndex>
<name></name>
<selectedRelationships>matched</selectedRelationships>
<source>
<groupId>673af2b8-8391-3580-0000-000000000000</groupId>
<id>ab213d84-4a44-36a0-0000-000000000000</id>
<type>PROCESSOR</type>
</source>
<zIndex>0</zIndex>
</connections>
<connections>
<id>99dd545c-b13f-3044-0000-000000000000</id>
<parentGroupId>673af2b8-8391-3580-0000-000000000000</parentGroupId>
<backPressureDataSizeThreshold>1 GB</backPressureDataSizeThreshold>
<backPressureObjectThreshold>10000</backPressureObjectThreshold>
<destination>
<groupId>673af2b8-8391-3580-0000-000000000000</groupId>
<id>ef2824c1-6117-382d-0000-000000000000</id>
<type>PROCESSOR</type>
</destination>
<flowFileExpiration>0 sec</flowFileExpiration>
<labelIndex>1</labelIndex>
<name></name>
<selectedRelationships>aggregations</selectedRelationships>
<source>
<groupId>673af2b8-8391-3580-0000-000000000000</groupId>
<id>1f23265f-36cc-3261-0000-000000000000</id>
<type>PROCESSOR</type>
</source>
<zIndex>0</zIndex>
</connections>
<controllerServices>
<id>e882e56f-0768-33e6-0000-000000000000</id>
<parentGroupId>673af2b8-8391-3580-0000-000000000000</parentGroupId>
<bundle>
<artifact>nifi-elasticsearch-client-service-nar</artifact>
<group>org.apache.nifi</group>
<version>1.7.1</version>
</bundle>
<comments></comments>
<descriptors>
<entry>
<key>el-cs-http-hosts</key>
<value>
<name>el-cs-http-hosts</name>
</value>
</entry>
<entry>
<key>el-cs-username</key>
<value>
<name>el-cs-username</name>
</value>
</entry>
<entry>
<key>el-cs-password</key>
<value>
<name>el-cs-password</name>
</value>
</entry>
<entry>
<key>el-cs-ssl-context-service</key>
<value>
<identifiesControllerService>org.apache.nifi.ssl.SSLContextService</identifiesControllerService>
<name>el-cs-ssl-context-service</name>
</value>
</entry>
<entry>
<key>el-cs-connect-timeout</key>
<value>
<name>el-cs-connect-timeout</name>
</value>
</entry>
<entry>
<key>el-cs-socket-timeout</key>
<value>
<name>el-cs-socket-timeout</name>
</value>
</entry>
<entry>
<key>el-cs-retry-timeout</key>
<value>
<name>el-cs-retry-timeout</name>
</value>
</entry>
<entry>
<key>el-cs-charset</key>
<value>
<name>el-cs-charset</name>
</value>
</entry>
</descriptors>
<name>ElasticSearchClientServiceImpl</name>
<persistsState>false</persistsState>
<properties>
<entry>
<key>el-cs-http-hosts</key>
<value>http://localhost:9200</value>
</entry>
<entry>
<key>el-cs-username</key>
</entry>
<entry>
<key>el-cs-password</key>
</entry>
<entry>
<key>el-cs-ssl-context-service</key>
</entry>
<entry>
<key>el-cs-connect-timeout</key>
</entry>
<entry>
<key>el-cs-socket-timeout</key>
</entry>
<entry>
<key>el-cs-retry-timeout</key>
</entry>
<entry>
<key>el-cs-charset</key>
</entry>
</properties>
<state>ENABLED</state>
<type>org.apache.nifi.elasticsearch.ElasticSearchClientServiceImpl</type>
</controllerServices>
<labels>
<id>3788ec25-4783-314d-0000-000000000000</id>
<parentGroupId>673af2b8-8391-3580-0000-000000000000</parentGroupId>
<position>
<x>807.3354095292739</x>
<y>600.2052321272406</y>
</position>
<height>185.5159149169922</height>
<label>Matched alerts logged to file and sent via email</label>
<style>
<entry>
<key>font-size</key>
<value>12px</value>
</entry>
</style>
<width>920.5878295898438</width>
</labels>
<labels>
<id>66d6fa0f-4ef4-32ed-0000-000000000000</id>
<parentGroupId>673af2b8-8391-3580-0000-000000000000</parentGroupId>
<position>
<x>18.78833616501612</x>
<y>295.9660658674749</y>
</position>
<height>172.60104370117188</height>
<label>Query Elasticsearch using JSON</label>
<style>
<entry>
<key>font-size</key>
<value>12px</value>
</entry>
</style>
<width>436.27984619140625</width>
</labels>
<labels>
<id>74a5dd9b-61f7-368c-0000-000000000000</id>
<parentGroupId>673af2b8-8391-3580-0000-000000000000</parentGroupId>
<position>
<x>581.9083465409926</x>
<y>302.6700453596624</y>
</position>
<height>172.60104370117188</height>
<label>Filter result to pick out the value we'll alert on</label>
<style>
<entry>
<key>font-size</key>
<value>12px</value>
</entry>
</style>
<width>436.27984619140625</width>
</labels>
<labels>
<id>b161c266-fec1-379c-0000-000000000000</id>
<parentGroupId>673af2b8-8391-3580-0000-000000000000</parentGroupId>
<position>
<x>1200.9927581620864</x>
<y>305.06900165849055</y>
</position>
<height>172.60104370117188</height>
<label>Used as our conditional, defined via NiFi expression language</label>
<style>
<entry>
<key>font-size</key>
<value>12px</value>
</entry>
</style>
<width>436.27984619140625</width>
</labels>
<labels>
<id>be04b34c-a10d-36a7-0000-000000000000</id>
<parentGroupId>673af2b8-8391-3580-0000-000000000000</parentGroupId>
<position>
<x>0.0</x>
<y>240.66749616035605</y>
</position>
<height>593.4108581542969</height>
<label>Alert on Aggregation</label>
<style>
<entry>
<key>background-color</key>
<value>#7ce2fc</value>
</entry>
<entry>
<key>font-size</key>
<value>14px</value>
</entry>
</style>
<width>1738.5302124023438</width>
</labels>
<labels>
<id>e7ab733d-9912-3a0a-0000-000000000000</id>
<parentGroupId>673af2b8-8391-3580-0000-000000000000</parentGroupId>
<position>
<x>500.94399472981075</x>
<y>0.0</y>
</position>
<height>225.33682250976562</height>
<label>Email Alert Example</label>
<style>
<entry>
<key>font-size</key>
<value>14px</value>
</entry>
</style>
<width>1121.8448791503906</width>
</labels>
<processors>
<id>1f23265f-36cc-3261-0000-000000000000</id>
<parentGroupId>673af2b8-8391-3580-0000-000000000000</parentGroupId>
<position>
<x>37.084568223370695</x>
<y>323.948290604468</y>
</position>
<bundle>
<artifact>nifi-elasticsearch-restapi-nar</artifact>
<group>org.apache.nifi</group>
<version>1.7.1</version>
</bundle>
<config>
<bulletinLevel>WARN</bulletinLevel>
<comments></comments>
<concurrentlySchedulableTaskCount>1</concurrentlySchedulableTaskCount>
<descriptors>
<entry>
<key>el-rest-query</key>
<value>
<name>el-rest-query</name>
</value>
</entry>
<entry>
<key>el-query-attribute</key>
<value>
<name>el-query-attribute</name>
</value>
</entry>
<entry>
<key>el-rest-fetch-index</key>
<value>
<name>el-rest-fetch-index</name>
</value>
</entry>
<entry>
<key>el-rest-type</key>
<value>
<name>el-rest-type</name>
</value>
</entry>
<entry>
<key>el-rest-client-service</key>
<value>
<identifiesControllerService>org.apache.nifi.elasticsearch.ElasticSearchClientService</identifiesControllerService>
<name>el-rest-client-service</name>
</value>
</entry>
<entry>
<key>el-rest-split-up-hits</key>
<value>
<name>el-rest-split-up-hits</name>
</value>
</entry>
<entry>
<key>el-rest-split-up-aggregations</key>
<value>
<name>el-rest-split-up-aggregations</name>
</value>
</entry>
</descriptors>
<executionNode>ALL</executionNode>
<lossTolerant>false</lossTolerant>
<penaltyDuration>30 sec</penaltyDuration>
<properties>
<entry>
<key>el-rest-query</key>
<value>{
"size": 0,
"_source": {
"excludes": []
},
"aggs": {
"2": {
"terms": {
"field": "SourceAddress",
"size": 20,
"order": {
"_term": "desc"
}
},
"aggs": {
"1": {
"avg": {
"field": "Bytes"
}
}
}
}
},
"stored_fields": [
"*"
],
"script_fields": {},
"docvalue_fields": [
"@timestamp",
"GenerateTime",
"ReceiveTime",
"StartTime",
"TimeLogged"
],
"query": {
"bool": {
"must": [
{
"query_string": {
"query": "_exists_:Bytes AND SourceAddress:78.133.112.106",
"analyze_wildcard": true,
"default_field": "*"
}
},
{
"range": {
"@timestamp": {
"gte": 1554930000000,
"lte": 1555016399999,
"format": "epoch_millis"
}
}
}
],
"filter": [],
"should": [],
"must_not": []
}
}
}</value>
</entry>
<entry>
<key>el-query-attribute</key>
<value>agg_result</value>
</entry>
<entry>
<key>el-rest-fetch-index</key>
<value>${now():format('yyyy.MM.dd'):prepend('filebeat-')}</value>
</entry>
<entry>
<key>el-rest-type</key>
</entry>
<entry>
<key>el-rest-client-service</key>
<value>e882e56f-0768-33e6-0000-000000000000</value>
</entry>
<entry>
<key>el-rest-split-up-hits</key>
<value>splitUp-no</value>
</entry>
<entry>
<key>el-rest-split-up-aggregations</key>
<value>splitUp-no</value>
</entry>
</properties>
<runDurationMillis>0</runDurationMillis>
<schedulingPeriod>60 sec</schedulingPeriod>
<schedulingStrategy>TIMER_DRIVEN</schedulingStrategy>
<yieldDuration>1 sec</yieldDuration>
</config>
<executionNodeRestricted>false</executionNodeRestricted>
<name>JsonQueryElasticsearch</name>
<relationships>
<autoTerminate>false</autoTerminate>
<name>aggregations</name>
</relationships>
<relationships>
<autoTerminate>true</autoTerminate>
<name>failure</name>
</relationships>
<relationships>
<autoTerminate>true</autoTerminate>
<name>hits</name>
</relationships>
<relationships>
<autoTerminate>true</autoTerminate>
<name>original</name>
</relationships>
<state>STOPPED</state>
<style/>
<type>org.apache.nifi.processors.elasticsearch.JsonQueryElasticsearch</type>
</processors>
<processors>
<id>7703dd54-5f75-3b30-0000-000000000000</id>
<parentGroupId>673af2b8-8391-3580-0000-000000000000</parentGroupId>
<position>
<x>839.1874653528021</x>
<y>624.4746133474912</y>
</position>
<bundle>
<artifact>nifi-standard-nar</artifact>
<group>org.apache.nifi</group>
<version>1.7.1</version>
</bundle>
<config>
<bulletinLevel>WARN</bulletinLevel>
<comments></comments>
<concurrentlySchedulableTaskCount>1</concurrentlySchedulableTaskCount>
<descriptors>
<entry>
<key>Directory</key>
<value>
<name>Directory</name>
</value>
</entry>
<entry>
<key>Conflict Resolution Strategy</key>
<value>
<name>Conflict Resolution Strategy</name>
</value>
</entry>
<entry>
<key>Create Missing Directories</key>
<value>
<name>Create Missing Directories</name>
</value>
</entry>
<entry>
<key>Maximum File Count</key>
<value>
<name>Maximum File Count</name>
</value>
</entry>
<entry>
<key>Last Modified Time</key>
<value>
<name>Last Modified Time</name>
</value>
</entry>
<entry>
<key>Permissions</key>
<value>
<name>Permissions</name>
</value>
</entry>
<entry>
<key>Owner</key>
<value>
<name>Owner</name>
</value>
</entry>
<entry>
<key>Group</key>
<value>
<name>Group</name>
</value>
</entry>
</descriptors>
<executionNode>ALL</executionNode>
<lossTolerant>false</lossTolerant>
<penaltyDuration>30 sec</penaltyDuration>
<properties>
<entry>
<key>Directory</key>
<value>/tmp</value>
</entry>
<entry>
<key>Conflict Resolution Strategy</key>
<value>fail</value>
</entry>
<entry>
<key>Create Missing Directories</key>
<value>true</value>
</entry>
<entry>
<key>Maximum File Count</key>
</entry>
<entry>
<key>Last Modified Time</key>
</entry>
<entry>
<key>Permissions</key>
</entry>
<entry>
<key>Owner</key>
</entry>
<entry>
<key>Group</key>
</entry>
</properties>
<runDurationMillis>0</runDurationMillis>
<schedulingPeriod>0 sec</schedulingPeriod>
<schedulingStrategy>TIMER_DRIVEN</schedulingStrategy>
<yieldDuration>1 sec</yieldDuration>
</config>
<executionNodeRestricted>false</executionNodeRestricted>
<name>PutFile</name>
<relationships>
<autoTerminate>true</autoTerminate>
<name>failure</name>
</relationships>
<relationships>
<autoTerminate>true</autoTerminate>
<name>success</name>
</relationships>
<state>STOPPED</state>
<style/>
<type>org.apache.nifi.processors.standard.PutFile</type>
</processors>
<processors>
<id>834fb412-0d0e-3dca-0000-000000000000</id>
<parentGroupId>673af2b8-8391-3580-0000-000000000000</parentGroupId>
<position>
<x>1352.2911030481146</x>
<y>622.2569162039365</y>
</position>
<bundle>
<artifact>nifi-standard-nar</artifact>
<group>org.apache.nifi</group>
<version>1.7.1</version>
</bundle>
<config>
<bulletinLevel>WARN</bulletinLevel>
<comments></comments>
<concurrentlySchedulableTaskCount>1</concurrentlySchedulableTaskCount>
<descriptors>
<entry>
<key>SMTP Hostname</key>
<value>
<name>SMTP Hostname</name>
</value>
</entry>
<entry>
<key>SMTP Port</key>
<value>
<name>SMTP Port</name>
</value>
</entry>
<entry>
<key>SMTP Username</key>
<value>
<name>SMTP Username</name>
</value>
</entry>
<entry>
<key>SMTP Password</key>
<value>
<name>SMTP Password</name>
</value>
</entry>
<entry>
<key>SMTP Auth</key>
<value>
<name>SMTP Auth</name>
</value>
</entry>
<entry>
<key>SMTP TLS</key>
<value>
<name>SMTP TLS</name>
</value>
</entry>
<entry>
<key>SMTP Socket Factory</key>
<value>
<name>SMTP Socket Factory</name>
</value>
</entry>
<entry>
<key>SMTP X-Mailer Header</key>
<value>
<name>SMTP X-Mailer Header</name>
</value>
</entry>
<entry>
<key>attribute-name-regex</key>
<value>
<name>attribute-name-regex</name>
</value>
</entry>
<entry>
<key>Content Type</key>
<value>
<name>Content Type</name>
</value>
</entry>
<entry>
<key>From</key>
<value>
<name>From</name>
</value>
</entry>
<entry>
<key>To</key>
<value>
<name>To</name>
</value>
</entry>
<entry>
<key>CC</key>
<value>
<name>CC</name>
</value>
</entry>
<entry>
<key>BCC</key>
<value>
<name>BCC</name>
</value>
</entry>
<entry>
<key>Subject</key>
<value>
<name>Subject</name>
</value>
</entry>
<entry>
<key>Message</key>
<value>
<name>Message</name>
</value>
</entry>
<entry>
<key>email-ff-content-as-message</key>
<value>
<name>email-ff-content-as-message</name>
</value>
</entry>
<entry>
<key>Attach File</key>
<value>
<name>Attach File</name>
</value>
</entry>
<entry>
<key>Include All Attributes In Message</key>
<value>
<name>Include All Attributes In Message</name>
</value>
</entry>
</descriptors>
<executionNode>ALL</executionNode>
<lossTolerant>false</lossTolerant>
<penaltyDuration>30 sec</penaltyDuration>
<properties>
<entry>
<key>SMTP Hostname</key>
<value>smtp.gmail.com</value>
</entry>
<entry>
<key>SMTP Port</key>
<value>465</value>
</entry>
<entry>
<key>SMTP Username</key>
<value>example@gmail.com</value>
</entry>
<entry>
<key>SMTP Password</key>
</entry>
<entry>
<key>SMTP Auth</key>
<value>true</value>
</entry>
<entry>
<key>SMTP TLS</key>
<value>false</value>
</entry>
<entry>
<key>SMTP Socket Factory</key>
<value>javax.net.ssl.SSLSocketFactory</value>
</entry>
<entry>
<key>SMTP X-Mailer Header</key>
<value>NiFi</value>
</entry>
<entry>
<key>attribute-name-regex</key>
</entry>
<entry>
<key>Content Type</key>
<value>text/plain</value>
</entry>
<entry>
<key>From</key>
<value>nifi@cybersift.io</value>
</entry>
<entry>
<key>To</key>
<value>example@gmail.com</value>
</entry>
<entry>
<key>CC</key>
</entry>
<entry>
<key>BCC</key>
</entry>
<entry>
<key>Subject</key>
<value>Alert!!!</value>
</entry>
<entry>
<key>Message</key>
</entry>
<entry>
<key>email-ff-content-as-message</key>
<value>true</value>
</entry>
<entry>
<key>Attach File</key>
<value>false</value>
</entry>
<entry>
<key>Include All Attributes In Message</key>
<value>false</value>
</entry>
</properties>
<runDurationMillis>0</runDurationMillis>
<schedulingPeriod>0 sec</schedulingPeriod>
<schedulingStrategy>TIMER_DRIVEN</schedulingStrategy>
<yieldDuration>1 sec</yieldDuration>
</config>
<executionNodeRestricted>false</executionNodeRestricted>
<name>PutEmail</name>
<relationships>
<autoTerminate>true</autoTerminate>
<name>failure</name>
</relationships>
<relationships>
<autoTerminate>true</autoTerminate>
<name>success</name>
</relationships>
<state>STOPPED</state>
<style/>
<type>org.apache.nifi.processors.standard.PutEmail</type>
</processors>
<processors>
<id>9002185e-06dd-367a-0000-000000000000</id>
<parentGroupId>673af2b8-8391-3580-0000-000000000000</parentGroupId>
<position>
<x>535.5642658899114</x>
<y>65.12584320588958</y>
</position>
<bundle>
<artifact>nifi-elasticsearch-nar</artifact>
<group>org.apache.nifi</group>
<version>1.9.2</version>
</bundle>
<config>
<bulletinLevel>WARN</bulletinLevel>
<comments></comments>
<concurrentlySchedulableTaskCount>1</concurrentlySchedulableTaskCount>
<descriptors>
<entry>
<key>elasticsearch-http-url</key>
<value>
<name>elasticsearch-http-url</name>
</value>
</entry>
<entry>
<key>SSL Context Service</key>
<value>
<identifiesControllerService>org.apache.nifi.ssl.SSLContextService</identifiesControllerService>
<name>SSL Context Service</name>
</value>
</entry>
<entry>
<key>Username</key>
<value>
<name>Username</name>
</value>
</entry>
<entry>
<key>Password</key>
<value>
<name>Password</name>
</value>
</entry>
<entry>
<key>elasticsearch-http-connect-timeout</key>
<value>
<name>elasticsearch-http-connect-timeout</name>
</value>
</entry>
<entry>
<key>elasticsearch-http-response-timeout</key>
<value>
<name>elasticsearch-http-response-timeout</name>
</value>
</entry>
<entry>
<key>proxy-configuration-service</key>
<value>
<identifiesControllerService>org.apache.nifi.proxy.ProxyConfigurationService</identifiesControllerService>
<name>proxy-configuration-service</name>
</value>
</entry>
<entry>
<key>elasticsearch-http-proxy-host</key>
<value>
<name>elasticsearch-http-proxy-host</name>
</value>
</entry>
<entry>
<key>elasticsearch-http-proxy-port</key>
<value>
<name>elasticsearch-http-proxy-port</name>
</value>
</entry>
<entry>
<key>proxy-username</key>
<value>
<name>proxy-username</name>
</value>
</entry>
<entry>
<key>proxy-password</key>
<value>
<name>proxy-password</name>
</value>
</entry>
<entry>
<key>scroll-es-query</key>
<value>
<name>scroll-es-query</name>
</value>
</entry>
<entry>
<key>scroll-es-scroll</key>
<value>
<name>scroll-es-scroll</name>
</value>
</entry>
<entry>
<key>scroll-es-size</key>
<value>
<name>scroll-es-size</name>
</value>
</entry>
<entry>
<key>scroll-es-index</key>
<value>
<name>scroll-es-index</name>
</value>
</entry>
<entry>
<key>scroll-es-type</key>
<value>
<name>scroll-es-type</name>
</value>
</entry>
<entry>
<key>scroll-es-fields</key>
<value>
<name>scroll-es-fields</name>
</value>
</entry>
<entry>
<key>scroll-es-sort</key>
<value>
<name>scroll-es-sort</name>
</value>
</entry>
</descriptors>
<executionNode>ALL</executionNode>
<lossTolerant>false</lossTolerant>
<penaltyDuration>30 sec</penaltyDuration>
<properties>
<entry>
<key>elasticsearch-http-url</key>
<value>http://localhost:9200</value>
</entry>
<entry>
<key>SSL Context Service</key>
</entry>
<entry>
<key>Username</key>
</entry>
<entry>
<key>Password</key>
</entry>
<entry>
<key>elasticsearch-http-connect-timeout</key>
<value>5 secs</value>
</entry>
<entry>
<key>elasticsearch-http-response-timeout</key>
<value>15 secs</value>
</entry>
<entry>
<key>proxy-configuration-service</key>
</entry>
<entry>
<key>elasticsearch-http-proxy-host</key>
</entry>
<entry>
<key>elasticsearch-http-proxy-port</key>
</entry>
<entry>
<key>proxy-username</key>
</entry>
<entry>
<key>proxy-password</key>
</entry>
<entry>
<key>scroll-es-query</key>
<value>DestinationAddress:104.20.177.69</value>
</entry>
<entry>
<key>scroll-es-scroll</key>
<value>1m</value>
</entry>
<entry>
<key>scroll-es-size</key>
<value>20</value>
</entry>
<entry>
<key>scroll-es-index</key>
<value>${now():format('yyyy.MM.dd'):prepend('filebeat-')}</value>
</entry>
<entry>
<key>scroll-es-type</key>
<value>syslog</value>
</entry>
<entry>
<key>scroll-es-fields</key>
</entry>
<entry>
<key>scroll-es-sort</key>
<value>_doc</value>
</entry>
</properties>
<runDurationMillis>0</runDurationMillis>
<schedulingPeriod>60 sec</schedulingPeriod>
<schedulingStrategy>TIMER_DRIVEN</schedulingStrategy>
<yieldDuration>1 sec</yieldDuration>
</config>
<executionNodeRestricted>false</executionNodeRestricted>
<name>ScrollElasticsearchHttp</name>
<relationships>
<autoTerminate>true</autoTerminate>
<name>failure</name>
</relationships>
<relationships>
<autoTerminate>false</autoTerminate>
<name>success</name>
</relationships>
<state>STOPPED</state>
<style/>
<type>org.apache.nifi.processors.elasticsearch.ScrollElasticsearchHttp</type>
</processors>
<processors>
<id>ab213d84-4a44-36a0-0000-000000000000</id>
<parentGroupId>673af2b8-8391-3580-0000-000000000000</parentGroupId>
<position>
<x>1232.7872708610962</x>
<y>331.4818826650002</y>
</position>
<bundle>
<artifact>nifi-standard-nar</artifact>
<group>org.apache.nifi</group>
<version>1.7.1</version>
</bundle>
<config>
<bulletinLevel>WARN</bulletinLevel>
<comments></comments>
<concurrentlySchedulableTaskCount>1</concurrentlySchedulableTaskCount>
<descriptors>
<entry>
<key>Routing Strategy</key>
<value>
<name>Routing Strategy</name>
</value>
</entry>
<entry>
<key>matched</key>
<value>
<name>matched</name>
</value>
</entry>
</descriptors>
<executionNode>ALL</executionNode>
<lossTolerant>false</lossTolerant>
<penaltyDuration>30 sec</penaltyDuration>
<properties>
<entry>
<key>Routing Strategy</key>
<value>Route to Property name</value>
</entry>
<entry>
<key>matched</key>
<value>${avg:gt(100)}</value>
</entry>
</properties>
<runDurationMillis>0</runDurationMillis>
<schedulingPeriod>0 sec</schedulingPeriod>
<schedulingStrategy>TIMER_DRIVEN</schedulingStrategy>
<yieldDuration>1 sec</yieldDuration>
</config>
<executionNodeRestricted>false</executionNodeRestricted>
<name>RouteOnAttribute</name>
<relationships>
<autoTerminate>false</autoTerminate>
<name>matched</name>
</relationships>
<relationships>
<autoTerminate>true</autoTerminate>
<name>unmatched</name>
</relationships>
<state>STOPPED</state>
<style/>
<type>org.apache.nifi.processors.standard.RouteOnAttribute</type>
</processors>
<processors>
<id>b2cef930-dcbc-38f5-0000-000000000000</id>
<parentGroupId>673af2b8-8391-3580-0000-000000000000</parentGroupId>
<position>
<x>1247.6495014856146</x>
<y>62.36552826448333</y>
</position>
<bundle>
<artifact>nifi-standard-nar</artifact>
<group>org.apache.nifi</group>
<version>1.7.1</version>
</bundle>
<config>
<bulletinLevel>WARN</bulletinLevel>
<comments></comments>
<concurrentlySchedulableTaskCount>1</concurrentlySchedulableTaskCount>
<descriptors>
<entry>
<key>SMTP Hostname</key>
<value>
<name>SMTP Hostname</name>
</value>
</entry>
<entry>
<key>SMTP Port</key>
<value>
<name>SMTP Port</name>
</value>
</entry>
<entry>
<key>SMTP Username</key>
<value>
<name>SMTP Username</name>
</value>
</entry>
<entry>
<key>SMTP Password</key>
<value>
<name>SMTP Password</name>
</value>
</entry>
<entry>
<key>SMTP Auth</key>
<value>
<name>SMTP Auth</name>
</value>
</entry>
<entry>
<key>SMTP TLS</key>
<value>
<name>SMTP TLS</name>
</value>
</entry>
<entry>
<key>SMTP Socket Factory</key>
<value>
<name>SMTP Socket Factory</name>
</value>
</entry>
<entry>
<key>SMTP X-Mailer Header</key>
<value>
<name>SMTP X-Mailer Header</name>
</value>
</entry>
<entry>
<key>attribute-name-regex</key>
<value>
<name>attribute-name-regex</name>
</value>
</entry>
<entry>
<key>Content Type</key>
<value>
<name>Content Type</name>
</value>
</entry>
<entry>
<key>From</key>
<value>
<name>From</name>
</value>
</entry>
<entry>
<key>To</key>
<value>
<name>To</name>
</value>
</entry>
<entry>
<key>CC</key>
<value>
<name>CC</name>
</value>
</entry>
<entry>
<key>BCC</key>
<value>
<name>BCC</name>
</value>
</entry>
<entry>
<key>Subject</key>
<value>
<name>Subject</name>
</value>
</entry>
<entry>
<key>Message</key>
<value>
<name>Message</name>
</value>
</entry>
<entry>
<key>email-ff-content-as-message</key>
<value>
<name>email-ff-content-as-message</name>
</value>
</entry>
<entry>
<key>Attach File</key>
<value>
<name>Attach File</name>
</value>
</entry>
<entry>
<key>Include All Attributes In Message</key>
<value>
<name>Include All Attributes In Message</name>
</value>
</entry>
</descriptors>
<executionNode>ALL</executionNode>
<lossTolerant>false</lossTolerant>
<penaltyDuration>30 sec</penaltyDuration>
<properties>
<entry>
<key>SMTP Hostname</key>
<value>smtp.gmail.com</value>
</entry>
<entry>
<key>SMTP Port</key>
<value>465</value>
</entry>
<entry>
<key>SMTP Username</key>
<value>example@gmail.com</value>
</entry>
<entry>
<key>SMTP Password</key>
</entry>
<entry>
<key>SMTP Auth</key>
<value>true</value>
</entry>
<entry>
<key>SMTP TLS</key>
<value>false</value>
</entry>
<entry>
<key>SMTP Socket Factory</key>
<value>javax.net.ssl.SSLSocketFactory</value>
</entry>
<entry>
<key>SMTP X-Mailer Header</key>
<value>NiFi</value>
</entry>
<entry>
<key>attribute-name-regex</key>
</entry>
<entry>
<key>Content Type</key>
<value>text/plain</value>
</entry>
<entry>
<key>From</key>
<value>nifi@cybersift.io</value>
</entry>
<entry>
<key>To</key>
</entry>
<entry>
<key>CC</key>
</entry>
<entry>
<key>BCC</key>
</entry>
<entry>
<key>Subject</key>
<value>Alert!!!</value>
</entry>
<entry>
<key>Message</key>
</entry>
<entry>
<key>email-ff-content-as-message</key>
<value>true</value>
</entry>
<entry>
<key>Attach File</key>
<value>false</value>
</entry>
<entry>
<key>Include All Attributes In Message</key>
<value>false</value>
</entry>
</properties>
<runDurationMillis>0</runDurationMillis>
<schedulingPeriod>0 sec</schedulingPeriod>
<schedulingStrategy>TIMER_DRIVEN</schedulingStrategy>
<yieldDuration>1 sec</yieldDuration>
</config>
<executionNodeRestricted>false</executionNodeRestricted>
<name>PutEmail</name>
<relationships>
<autoTerminate>true</autoTerminate>
<name>failure</name>
</relationships>
<relationships>
<autoTerminate>true</autoTerminate>
<name>success</name>
</relationships>
<state>STOPPED</state>
<style/>
<type>org.apache.nifi.processors.standard.PutEmail</type>
</processors>
<processors>
<id>ef2824c1-6117-382d-0000-000000000000</id>
<parentGroupId>673af2b8-8391-3580-0000-000000000000</parentGroupId>
<position>
<x>615.0254351699864</x>
<y>331.48197255866677</y>
</position>
<bundle>
<artifact>nifi-standard-nar</artifact>
<group>org.apache.nifi</group>
<version>1.7.1</version>
</bundle>
<config>
<bulletinLevel>WARN</bulletinLevel>
<comments></comments>
<concurrentlySchedulableTaskCount>1</concurrentlySchedulableTaskCount>
<descriptors>
<entry>
<key>Destination</key>
<value>
<name>Destination</name>
</value>
</entry>
<entry>
<key>Return Type</key>
<value>
<name>Return Type</name>
</value>
</entry>
<entry>
<key>Path Not Found Behavior</key>
<value>
<name>Path Not Found Behavior</name>
</value>
</entry>
<entry>
<key>Null Value Representation</key>
<value>
<name>Null Value Representation</name>
</value>
</entry>
<entry>
<key>avg</key>
<value>
<name>avg</name>
</value>
</entry>
</descriptors>
<executionNode>ALL</executionNode>
<lossTolerant>false</lossTolerant>
<penaltyDuration>30 sec</penaltyDuration>
<properties>
<entry>
<key>Destination</key>
<value>flowfile-attribute</value>
</entry>
<entry>
<key>Return Type</key>
<value>auto-detect</value>
</entry>
<entry>
<key>Path Not Found Behavior</key>
<value>ignore</value>
</entry>
<entry>
<key>Null Value Representation</key>
<value>empty string</value>
</entry>
<entry>
<key>avg</key>
<value>$.2.buckets[0].1.value</value>
</entry>
</properties>
<runDurationMillis>0</runDurationMillis>
<schedulingPeriod>0 sec</schedulingPeriod>
<schedulingStrategy>TIMER_DRIVEN</schedulingStrategy>
<yieldDuration>1 sec</yieldDuration>
</config>
<executionNodeRestricted>false</executionNodeRestricted>
<name>EvaluateJsonPath</name>
<relationships>
<autoTerminate>true</autoTerminate>
<name>failure</name>
</relationships>
<relationships>
<autoTerminate>false</autoTerminate>
<name>matched</name>
</relationships>
<relationships>
<autoTerminate>true</autoTerminate>
<name>unmatched</name>
</relationships>
<state>STOPPED</state>
<style/>
<type>org.apache.nifi.processors.standard.EvaluateJsonPath</type>
</processors>
</snippet>
<timestamp>04/11/2019 14:58:33 CEST</timestamp>
</template>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
You can’t perform that action at this time.