Yelp / elastalert

Easy & Flexible Alerting With ElasticSearch
https://elastalert.readthedocs.org
Apache License 2.0
8k stars 1.73k forks source link

Range timestamp filter #3289

Open Nib0ort opened 1 year ago

Nib0ort commented 1 year ago

Hello I want this rule to send me an email when elastalert detect at least 5 times in less 10 secondes a certain type of log containing a string of characters. Here my rule, but I dont get email with 6 logs sent in less 10 secondes. I'm using this command to send logs : logger -t corosync is down

` es_host: ip es_port: port name: TEST type: frequency index: filebeat-* filter:

Thanks for helping