Open amribrahim opened 2 years ago
Hello! I referred to the elastalert docs for writing rules and found this query that matches your problem:
- query:
query_string:
query: "field: value OR otherfield: othervalue"
So, why don't you enclose the whole thing inside url.domain
in double quotes? Let's see if that works
Hello i need to make the following filter in elastalert rule
so i need to test that url.domain start with apis keyword or test keyword, but when i test the rule it give error in or condition so how can i solve this issue
Thanks