Skip to content

About

Go application for log monitoring

Resources

Stars

1 star

Watchers

0 watching

Forks

Latest commit

Β 

History

20 Commits

Folders and files

Repository files navigation

NLP based Alert Engine - Phase 0: Foundation & Proof of Concept

An ALERT SYSTEM been developed using Cursor

A Go-based alert engine for monitoring application logs in OpenShift environments with real-time alerting via Slack.

Scope

Goal: Validate the concept with minimal viable alerting

Components to Build

  • Simple Log Ingestion - OpenShift Logging Vector + Kafka pipeline
  • Basic Alert Engine - Simple rule-based alerting (no NLP engine)
  • Single notification channel - Slack integration only
  • Minimal UI - Command Line or simple web form for alert creation

Deliverables

  • Working log pipeline from OpenShift pods to Kafka
  • Basic threshold-based alerts (count, keyword matching)
  • Slack notification working
  • Single hard-coded alert rule validation

Success Criteria

  • Can detect "ERROR" logs exceeding count threshold
  • Can send Slack notification within 30 seconds
  • No data loss in log pipeline

Vision

For the long-term vision and NLP-based alert pattern analysis that will guide future development phases, refer to:

🧠 NLP Alert Patterns Analysis - Comprehensive analysis of natural language processing patterns for intelligent log monitoring and advanced alert detection capabilities.

πŸš€ Overview

The Alert Engine is a cloud-native solution designed to monitor application logs from OpenShift/Kubernetes environments, evaluate them against configurable alert rules, and send notifications to Slack channels. This implementation represents Phase 0 of a comprehensive log monitoring system.

Key Features

  • Real-time Log Processing: Consumes log messages from Kafka streams
  • Flexible Alert Rules: Configurable rules based on log level, namespace, service, keywords, and thresholds
  • Slack Integration: Rich notification messages with severity-based formatting
  • High Performance: Redis-backed state management with horizontal scaling support
  • Cloud-Native: Designed for OpenShift/Kubernetes with proper RBAC and security
  • RESTful API: Full API for managing alert rules and monitoring system status

πŸ—οΈ Architecture

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚   OpenShift     β”‚    β”‚   AMQ        β”‚    β”‚   Alert         β”‚    β”‚   Slack     β”‚
β”‚   Pods/Logs     │───▢│   Streams    │───▢│   Engine        │───▢│   Webhook   β”‚
β”‚                 β”‚    β”‚   (Kafka)    β”‚    β”‚   (Go Service)  β”‚    β”‚             β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
         β”‚                       β”‚                       β”‚
         β”‚                       β”‚                       β”‚
         β–Ό                       β–Ό                       β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚   OpenShift     β”‚    β”‚   Redis      β”‚    β”‚   REST API      β”‚
β”‚   Logging       β”‚    β”‚   (State)    β”‚    β”‚   (Management)  β”‚
β”‚   (Vector)      β”‚    β”‚              β”‚    β”‚                 β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

πŸ› οΈ Technology Stack

  • Language: Go 1.21+
  • Framework: Gin (HTTP router)
  • Message Streaming: Apache Kafka (Red Hat AMQ Streams)
  • State Storage: Redis
  • Container Platform: OpenShift 4.12+
  • Notifications: Slack Webhooks
  • Monitoring: Prometheus metrics

πŸ“ Project Structure

alert-engine/
β”œβ”€β”€ bin/                           # Binary executables
β”œβ”€β”€ cmd/                          # Application entry points
β”œβ”€β”€ configs/                      # Configuration files
β”‚   β”œβ”€β”€ config.yaml              # Main application configuration
β”‚   └── README.md                # Configuration documentation
β”œβ”€β”€ deployments/                 # Deployment manifests
β”‚   β”œβ”€β”€ alert-engine/           # Alert Engine OpenShift deployment
β”‚   β”‚   β”œβ”€β”€ BUILD_SUMMARY.md    # Build summary documentation
β”‚   β”‚   β”œβ”€β”€ build.sh            # Build script
β”‚   β”‚   β”œβ”€β”€ configmap.yaml      # ConfigMap manifest
β”‚   β”‚   β”œβ”€β”€ deployment.yaml     # Deployment manifest
β”‚   β”‚   β”œβ”€β”€ Dockerfile          # Container image definition
β”‚   β”‚   β”œβ”€β”€ kustomization.yaml  # Kustomize configuration
β”‚   β”‚   β”œβ”€β”€ namespace.yaml      # Namespace manifest
β”‚   β”‚   β”œβ”€β”€ networkpolicy.yaml  # Network policy manifest
β”‚   β”‚   β”œβ”€β”€ README.md           # Deployment documentation
β”‚   β”‚   β”œβ”€β”€ secret.yaml         # Secret manifest
β”‚   β”‚   β”œβ”€β”€ service.yaml        # Service manifest
β”‚   β”‚   β”œβ”€β”€ serviceaccount.yaml # Service account manifest
β”‚   β”‚   └── update-image.sh     # Image update script
β”‚   └── phase0/                 # Phase 0 deployment manifests
β”‚       └── payment-error-job.yaml # Payment error test job
β”œβ”€β”€ inputs/                      # Project documentation and analysis
β”‚   β”œβ”€β”€ coverage_analysis.md     # Test coverage analysis
β”‚   β”œβ”€β”€ Log Monitoring PRD.pdf   # Product requirements document
β”‚   └── nlp_alert_patterns.md    # NLP pattern analysis
β”œβ”€β”€ internal/                    # Internal application packages
β”‚   β”œβ”€β”€ alerting/               # Alert evaluation engine
β”‚   β”‚   β”œβ”€β”€ engine.go           # Main alert evaluation engine
β”‚   β”‚   β”œβ”€β”€ engine_test.go      # Engine unit tests
β”‚   β”‚   β”œβ”€β”€ evaluator.go        # Rule evaluation logic
β”‚   β”‚   β”œβ”€β”€ evaluator_test.go   # Evaluator unit tests
β”‚   β”‚   β”œβ”€β”€ rules.go            # Rule management and validation
β”‚   β”‚   β”œβ”€β”€ rules_test.go       # Rules unit tests
β”‚   β”‚   β”œβ”€β”€ mock_test.go        # Mock setup for tests
β”‚   β”‚   β”œβ”€β”€ fixtures/           # Test data fixtures
β”‚   β”‚   β”‚   β”œβ”€β”€ test_logs.json
β”‚   β”‚   β”‚   └── test_rules.json
β”‚   β”‚   β”œβ”€β”€ mocks/              # Generated mocks
β”‚   β”‚   β”‚   β”œβ”€β”€ mock_notifier.go
β”‚   β”‚   β”‚   └── mock_state_store.go
β”‚   β”‚   └── README.md           # Alerting package documentation
β”‚   β”œβ”€β”€ api/                    # HTTP API layer
β”‚   β”‚   β”œβ”€β”€ handlers.go         # HTTP API handlers
β”‚   β”‚   β”œβ”€β”€ handlers_test.go    # Handler unit tests
β”‚   β”‚   β”œβ”€β”€ routes.go           # API route definitions
β”‚   β”‚   β”œβ”€β”€ integration_test.go # API integration tests
β”‚   β”‚   β”œβ”€β”€ fixtures/           # Test data fixtures
β”‚   β”‚   β”‚   β”œβ”€β”€ test_requests.json
β”‚   β”‚   β”‚   └── test_responses.json
β”‚   β”‚   β”œβ”€β”€ mocks/              # Generated mocks
β”‚   β”‚   β”‚   β”œβ”€β”€ mock_alert_engine.go
β”‚   β”‚   β”‚   └── mock_state_store.go
β”‚   β”‚   └── README.md           # API package documentation
β”‚   β”œβ”€β”€ kafka/                  # Kafka integration
β”‚   β”‚   β”œβ”€β”€ consumer.go         # Kafka consumer implementation
β”‚   β”‚   β”œβ”€β”€ consumer_test.go    # Consumer unit tests
β”‚   β”‚   β”œβ”€β”€ processor.go        # Log message processing
β”‚   β”‚   β”œβ”€β”€ processor_test.go   # Processor unit tests
β”‚   β”‚   β”œβ”€β”€ integration_test.go # Kafka integration tests
β”‚   β”‚   β”œβ”€β”€ fixtures/           # Test data fixtures
β”‚   β”‚   β”‚   β”œβ”€β”€ test_configs.json
β”‚   β”‚   β”‚   └── test_messages.json
β”‚   β”‚   β”œβ”€β”€ mocks/              # Generated mocks
β”‚   β”‚   β”‚   β”œβ”€β”€ mock_alert_engine.go
β”‚   β”‚   β”‚   β”œβ”€β”€ mock_kafka_reader.go
β”‚   β”‚   β”‚   └── mock_state_store.go
β”‚   β”‚   β”œβ”€β”€ testcontainers/     # Test container setup
β”‚   β”‚   β”‚   └── kafka_container.go
β”‚   β”‚   └── README.md           # Kafka package documentation
β”‚   β”œβ”€β”€ notifications/          # Notification integrations
β”‚   β”‚   β”œβ”€β”€ interfaces.go       # Notification interfaces
β”‚   β”‚   β”œβ”€β”€ interfaces_test.go  # Interface unit tests
β”‚   β”‚   β”œβ”€β”€ slack.go            # Slack integration
β”‚   β”‚   β”œβ”€β”€ slack_test.go       # Slack unit tests
β”‚   β”‚   β”œβ”€β”€ integration_test.go # Notification integration tests
β”‚   β”‚   β”œβ”€β”€ fixtures/           # Test data fixtures
β”‚   β”‚   β”‚   └── test_alerts.json
β”‚   β”‚   β”œβ”€β”€ mocks/              # Generated mocks
β”‚   β”‚   β”‚   β”œβ”€β”€ mock_http_client.go
β”‚   β”‚   β”‚   └── mock_http_server.go
β”‚   β”‚   └── README.md           # Notifications package documentation
β”‚   └── storage/                # Data storage layer
β”‚       β”œβ”€β”€ redis.go            # Redis storage implementation
β”‚       β”œβ”€β”€ redis_test.go       # Redis unit tests
β”‚       β”œβ”€β”€ integration_test.go # Storage integration tests
β”‚       β”œβ”€β”€ redis_container.go  # Redis test container setup
β”‚       β”œβ”€β”€ test_data.json      # Test data for storage
β”‚       └── README.md           # Storage package documentation
β”œβ”€β”€ local_e2e/                  # End-to-end testing setup
β”‚   β”œβ”€β”€ setup/                  # E2E environment setup
β”‚   β”‚   β”œβ”€β”€ config_local_e2e.yaml
β”‚   β”‚   β”œβ”€β”€ docker-compose-local-e2e.yml
β”‚   β”‚   β”œβ”€β”€ mock_log_forwarder.py
β”‚   β”‚   β”œβ”€β”€ requirements.txt
β”‚   β”‚   β”œβ”€β”€ setup_local_e2e.sh
β”‚   β”‚   β”œβ”€β”€ start_alert_engine.sh
β”‚   β”‚   β”œβ”€β”€ teardown_local_e2e.sh
β”‚   β”‚   β”œβ”€β”€ test_slack.sh
β”‚   β”‚   └── README.md
β”‚   └── tests/                  # E2E test cases
β”‚       β”œβ”€β”€ comprehensive_e2e_test_config.json
β”‚       β”œβ”€β”€ run_e2e_tests.sh
β”‚       └── README.md
β”œβ”€β”€ pkg/                        # Public packages
β”‚   └── models/                 # Data models
β”‚       β”œβ”€β”€ alert.go            # Alert rule models
β”‚       β”œβ”€β”€ alert_test.go       # Alert model tests
β”‚       β”œβ”€β”€ log.go              # Log entry models
β”‚       β”œβ”€β”€ log_test.go         # Log model tests
β”‚       β”œβ”€β”€ fixtures/           # Test data fixtures
β”‚       β”‚   β”œβ”€β”€ test_alerts.json
β”‚       β”‚   └── test_logs.json
β”‚       └── README.md           # Models package documentation
β”œβ”€β”€ scripts/                    # Build and test automation
β”‚   β”œβ”€β”€ cleanup_openshift_infrastructure.sh # OpenShift cleanup script
β”‚   β”œβ”€β”€ docker-compose.test.yml # Test environment setup
β”‚   β”œβ”€β”€ openshift_utils.sh      # Shared OpenShift utilities
β”‚   β”œβ”€β”€ prompt.md               # Development prompts and guidance
β”‚   β”œβ”€β”€ run_integration_tests.sh # Integration test runner
β”‚   β”œβ”€β”€ run_kafka_integration_tests.sh # Kafka-specific test runner
β”‚   β”œβ”€β”€ run_unit_tests.sh       # Unit test runner
β”‚   β”œβ”€β”€ setup_openshift_infrastructure.sh # OpenShift setup script
β”‚   β”œβ”€β”€ test_strategy.md        # Testing strategy documentation
β”‚   β”œβ”€β”€ validate_openshift_infrastructure.sh # OpenShift validation script
β”‚   β”œβ”€β”€ verify_resources_before_cleanup.sh # Pre-cleanup verification
β”‚   └── README.md               # Scripts documentation
β”œβ”€β”€ alert_engine_infra_setup.md # Infrastructure setup guide
β”œβ”€β”€ go.mod                      # Go module definition
β”œβ”€β”€ go.sum                      # Go module checksums
β”œβ”€β”€ main                        # Compiled binary
β”œβ”€β”€ Makefile                    # Build automation
└── README.md                   # This file

🚦 Prerequisites

  • Go 1.21 or later
  • Access to OpenShift/Kubernetes cluster
  • Redis instance
  • Kafka cluster (Red Hat AMQ Streams)
  • Slack workspace with webhook permissions
  • Openshift AI

πŸ“‹ Infrastructure Setup

IMPORTANT: Before proceeding with the Alert Engine setup, you must first install and configure the required infrastructure components on your OpenShift cluster.

πŸ‘‰ OpenShift Infrastructure Setup Guide

Key infrastructure components to install (15-20 minutes total):

  • Red Hat AMQ Streams: Install operator and deploy 3-node Kafka cluster with application-logs topic
  • Redis Enterprise: Install operator and create database with ReJSON/TimeSeries modules for state management
  • OpenShift Logging: Install operator and configure ClusterLogForwarder to route application logs to Kafka
  • RBAC & Security: Create service accounts, role bindings, and network policies for secure log collection
  • Verification: Test connectivity between components and validate log forwarding pipeline

Complete the infrastructure setup before proceeding with the local development or deployment steps below.

πŸ”§ Setup Instructions [To be Updated]

1. Local Development Setup

For comprehensive local development setup with end-to-end testing capabilities, refer to:

2. Configuration

For detailed configuration instructions including environment variables, configuration files, and deployment settings, refer to:

πŸ“‹ Configuration Guide - Complete configuration documentation with examples for local development, testing, and production deployment.

πŸ“š API Documentation

For comprehensive API documentation including endpoints, request/response formats, and usage examples, refer to:

πŸ“‹ API Documentation - Complete REST API documentation with detailed endpoint specifications, authentication, and integration examples.

🚒 Getting started on Phase 1

  • The Alert Engine is complete for Phase0. Run the following commands to get started
make infra-setup
make infra-validate
make test-all
oc apply -f deployments/phase0/payment-error-job.yaml
make build-and-deploy
make logs
make health
  • set an alert rule
curl -s -X POST "http://localhost:8080/api/v1/rules" \
  -H "Content-Type: application/json" \
  -d '{
    "id": "perfect-payment-alert",
    "name": "Perfect Payment Alert", 
    "description": "Exactly matches current payment logs",
    "enabled": true,
    "conditions": {
      "log_level": "error",
      "namespace": "phase0-logs",
      "service": "payment-service",
      "keywords": ["Payment", "failed"],
      "threshold": 1,
      "time_window": 60000000000,
      "operator": "gte"
    },
    "actions": {
      "slack_webhook": "https://hooks.slack.com/services/YOUR_WEBHOOK_URL",
      "channel": "#alert-channel", # Your own channel
      "severity": "high"
    }
  }'

Alert Engine v1.0.0 - Phase 0: Foundation & Proof of Concept

About

Go application for log monitoring

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages