Closed weslambert closed 4 years ago
It seems that we need to remark/remove use_count_query
(and doc_type
is no longer needed)
This is included in securityonion-elastic - 20190510-1ubuntu1securityonion83
which is now available for testing at ppa:securityonion/test.
Looks good 👍
INFO:elastalert:Queried rule Security Onion Elastalert - New Term Alert from 2020-01-14 12:49 UTC to 2020-01-14 12:50 UTC: 0 hits ERROR:root:Traceback (most recent call last): File "/opt/elastalert/elastalert/elastalert.py", line 1270, in handle_rule_execution num_matches = self.run_rule(rule, endtime, rule.get('initial_starttime')) File "/opt/elastalert/elastalert/elastalert.py", line 905, in run_rule if not self.run_query(rule, rule['starttime'], endtime): File "/opt/elastalert/elastalert/elastalert.py", line 645, in run_query rule_inst.add_count_data(data) File "/opt/elastalert/elastalert/ruletypes.py", line 84, in add_count_data raise NotImplementedError() NotImplementedError