Open goveebee opened 6 years ago
You posted config.yaml twice instead of your rule.
Edited. Now, both files are there.. :)
ElastAlert will trigger an alert as soon as it sees 500 documents within the most recent 10 minutes. Perhaps when looking at Kibana you are seeing 500 documents over a slightly longer time period.
You should be able to see the exact amount of hits for each query being made in the logs and in elastalert_status index.
I don't think there is any bug or issue here unless you can show some data of a discrepancy.
I'm sure the data I see is the data that Elastalert should trig on. Still it takes up to five minutes, no less than two. Even after multiple query runs.
You can see from the logs exactly what time period is being queried. From that you should able to see where the discrepancy is.
You could post them here, otherwise there's not anything I can do to help.
A screenshot from the same time showing the relevant data in Kibana would help too.
I'm having some problems with a delay of my alerts. I see the data in Kibana but it still takes up to 5 mins before the alerts are triggered. The ElastAlert-query is run a couple of times with data in Elastic, but without triggering.
Rule:
Config: