-
Notifications
You must be signed in to change notification settings - Fork 3
/
elastalert_lambda.py
69 lines (55 loc) · 1.67 KB
/
elastalert_lambda.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
import os
import sys
import datetime
import shlex
from elastalert import elastalert
from elastalert import create_index
class TmpSysArgv(object):
def __enter__(self):
self.orig_argv = sys.argv
def __exit__(self, *args, **kwargs):
sys.argv = self.orig_argv
def handler(event, context):
print("Starting up ElastAlert")
args = shlex.split(event.get('ARGS', os.getenv('ARGS', '')))
if '--end' not in args:
args.extend([
'--end',
datetime.datetime.utcnow().isoformat(),
])
if '--config' not in args:
args.extend(['--config', 'config.yaml'])
print("Using arguments: `%s`" % args)
if "EA_CREATE_INDEX" in os.environ:
if "EA_CREATE_INDEX_ARGS" in os.environ:
ci_args = ["elastalert-create-index"] + shlex.split(
os.getenv("EA_CREATE_INDEX_ARGS"))
else:
config_index = args.index("--config")
ci_args = [
"elastalert-create-index",
args[config_index],
args[config_index + 1]
]
print("Creating index for elastalert with args: %s" % (ci_args, ))
with TmpSysArgv():
sys.argv = ci_args
create_index.main()
try:
elastalert.main(args)
except SystemExit as exc:
if exc.args[0] == 0:
print("ElastAlert run successfully!")
return
raise
if __name__ == "__main__":
"""
Purely for local testing
"""
import json
import sys
import select
event = {}
if select.select([sys.stdin,], [], [], 0.0)[0]:
event = json.loads(sys.stdin.read())
handler(event, None)