awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Yelp avatar

Yelp/elastalert

0
View on GitHub↗
7,994 stars·1,693 forks·Python·Apache-2.0·14 viewselastalert.readthedocs.org↗

Elastalert

ElastAlert is an alerting framework and query monitor for Elasticsearch. It functions as a real-time log monitoring tool and event notification engine that scans indices for specific patterns to trigger automated alerts when predefined rules are matched.

The system distinguishes itself through specialized detection logic, including event spike detection, event frequency monitoring, field change tracking, and the identification of new terms within data fields. It handles notification noise via stateful alert suppression to prevent redundant messages and provides time-windowed aggregation to group multiple events into single summary reports.

The framework covers a broad range of operational capabilities, including log anomaly detection, infrastructure monitoring, and historical data auditing. It features a pluggable system for dispatching notifications to third-party messaging platforms and ticketing systems, and includes command-line tools for debugging rules against historical datasets.

Features

  • Elasticsearch Alerting - Monitors Elasticsearch indices for specific patterns and triggers automated notifications when predefined rules are matched.
  • Field - Triggers alerts when a specific field value changes between documents sharing the same identifier.
  • Event Filtering Rules - Scans indices using predefined query filters to identify specific documents that trigger an alert notification.
  • Event Spike Detection - Triggers alerts when the rate of events increases by a specific factor compared to previous periods.
  • Polling Mechanisms - Periodically queries the data store for new documents within a moving time window to detect matching events.
  • Notification Dispatchers - Provides a notification dispatcher that routes alerts to external services including chat and incident management platforms.
  • Anomaly Detection - Identifies unusual spikes in event frequency or the appearance of new terms in system logs.
  • Data Pattern Monitoring - Scans indices for anomalies and spikes to trigger alerts when predefined data conditions are met.
  • Elasticsearch Alerting Frameworks - Functions as a comprehensive alerting framework and query monitor for Elasticsearch indices.
  • Elasticsearch Query Monitors - Executes periodic queries against Elasticsearch to track field changes and identify new terms in data.
  • Index Pattern Monitoring - Scans data indices for specific patterns to trigger notifications when predefined rules are met.
  • Infrastructure Monitoring - Tracks field changes and monitors data patterns to detect system failures or performance degradation.
  • Event Frequency Monitoring - Provides alerting based on the frequency of specific events occurring within a defined time window.
  • New Term Identification - Triggers alerts when a previously unseen value appears in one or more specified data fields.
  • Log Stream Monitors - Scans data streams for anomalies, spikes, and frequency changes to detect operational issues.
  • Stateful Alert Suppression - Prevents redundant notifications for the same event by tracking the timing and attributes of previous alerts.
  • Monitoring Logic Auditing - Tests alert rules against past data and scans specific time windows to verify monitoring logic.
  • Historical Data Querying Interfaces - Allows setting start and stop timestamps for the monitoring process to analyze historical data.
  • Time-Window Aggregations - Buffers matching documents over a set period to send a single summary report instead of individual alerts.
  • Developer Notification Handlers - Provides a modular system of alert dispatchers to deliver formatted notifications to external communication platforms.
  • Index Pattern Resolvers - Resolves target search indices at runtime using glob patterns to support time-rotated or dated indices.
  • Incident Notification Services - Dispatches automated alerts from data queries to external messaging platforms and ticketing systems.
  • Duplicate Alert Suppression - Prevents redundant notifications by enforcing a minimum time interval between alerts or grouping by field keys.
  • Alerting Logic Engines - Supports implementing custom rule types and handlers for specialized monitoring paradigms and unique notification targets.
  • Third-Party Integrations - Dispatches match alerts to external communication platforms, ticketing systems, or messaging applications.
  • Alerting Rule Validators - Allows users to test alerting rules against historical data to verify filter matches and simulate triggers.
  • Notification Aggregation - Groups multiple events occurring over a period into a single notification delivered on a scheduled basis.
  • Observability Data Aggregators - Combines individual match events into periodic summaries and aggregate counts for specific data fields.
  • Alert Message Customization - Formats notification messages using custom text, string arguments, or a restricted list of document fields.
  • AI & Machine Learning - Modular rules-based alerting system.
  • Data Analytics and Applications - Framework for alerting on anomalies in Elasticsearch data.
  • Data Applications - Framework for alerting on anomalies and patterns in Elasticsearch.
  • Detection and Alerting Platforms - Framework for alerting on anomalies in Elasticsearch data.
  • Monitoring and Observability - Flexible alerting framework for Elasticsearch data.
  • Alerting Tools - Framework for alerting on anomalies in Elasticsearch data.

Star history

Star history chart for yelp/elastalertStar history chart for yelp/elastalert

How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does yelp/elastalert do?

ElastAlert is an alerting framework and query monitor for Elasticsearch. It functions as a real-time log monitoring tool and event notification engine that scans indices for specific patterns to trigger automated alerts when predefined rules are matched.

What are the main features of yelp/elastalert?

The main features of yelp/elastalert are: Elasticsearch Alerting, Field, Event Filtering Rules, Event Spike Detection, Polling Mechanisms, Notification Dispatchers, Anomaly Detection, Data Pattern Monitoring.

What are some open-source alternatives to yelp/elastalert?

Open-source alternatives to yelp/elastalert include: greptimeteam/greptimedb — GreptimeDB is a distributed, open-source time-series database built for unified observability. It stores and queries… brexhq/substation — Substation is a toolkit for routing, normalizing, and enriching security event and audit logs. etsy/411 — An Alert Management Web Application. deepops-ai/deepops — DeepOps is a full-stack observability platform and application performance monitoring tool. It serves as a distributed… tautulli/tautulli — Tautulli is a monitoring tool and administration interface for Plex Media Servers. It tracks real-time streaming… elastic/elasticsearch-php — This project is a software development kit and cluster management tool for PHP. It serves as a full-text search SDK…

Open-source alternatives to Elastalert

Similar open-source projects, ranked by how many features they share with Elastalert.
  • greptimeteam/greptimedbGreptimeTeam avatar

    GreptimeTeam/greptimedb

    5,968View on GitHub↗

    GreptimeDB is a distributed, open-source time-series database built for unified observability. It stores and queries metrics, logs, and traces together in a single columnar engine, supporting both SQL and PromQL for analysis. The database is designed as a Kubernetes-native operator with a decoupled compute and storage architecture, enabling horizontal scaling and multi-region deployment. What distinguishes GreptimeDB is its role as a multi-protocol ingestion gateway, accepting data through OpenTelemetry, Prometheus Remote Write, InfluxDB, Loki, Elasticsearch, Kafka, and MQTT protocols without

    Rustanalyticscloud-nativedatabase
    View on GitHub↗5,968
  • brexhq/substationbrexhq avatar

    brexhq/substation

    402View on GitHub↗

    Substation is a toolkit for routing, normalizing, and enriching security event and audit logs.

    Go
    View on GitHub↗402
  • etsy/411etsy avatar

    etsy/411

    968View on GitHub↗

    An Alert Management Web Application

    PHP
    View on GitHub↗968
  • deepops-ai/deepopsdeepops-ai avatar

    deepops-ai/deepops

    3,965View on GitHub↗

    DeepOps is a full-stack observability platform and application performance monitoring tool. It serves as a distributed service observability suite designed to track response times, resource usage, and service health across diverse infrastructure layers. The platform functions as a cross-stack telemetry aggregator, unifying metrics and logs into a single data stream. It incorporates a heuristic anomaly detection system that analyzes performance baselines to identify statistical outliers and predict operational failures. The system covers a broad range of monitoring capabilities, including rea

    TypeScriptapmjaegerobservability
    View on GitHub↗3,965
See all 30 alternatives to Elastalert→