Open drboone opened 4 years ago
We also recommend asking questions on the Gitter channel https://gitter.im/Yelp/elastalert
I eventually figured out that the setup script makes the index correctly, but that it occasionally gets remade with a different schema somehow. Attached is the diff that sorted out my problem for elasticsearch v6.
@drboone
Should make a pull request
Does Elasticsearch 6 and 7 need to have different config files?
I don't know. Would make sense. It currently doesn't have mappings for 7 in that subtree.
@drboone , it also fixed my issue as some date field (unix_ms type) and caused alerts not being processed! I'll add this patch my running EA with this. Hopefully, this can be merged in the base code!
I did not create the schema attached below.. I did run the create script at install time.
There are two concerns here:
It would help if the documentation talked about how these schemas are established. I haven't been able to find that, but maybe I'm blind.
ES says the schema is: elastalert.txt
ES v6.8.9, Elastalert v0.2.4.