Open luatdeptrai opened 11 months ago
ElastAlert is no longer maintained. Please use ElastAlert2 instead.
ElastAlert is no longer maintained. Please use ElastAlert2 instead.
So how can I do it with elastalert2 pls help..
Ask your own questions. https://github.com/jertel/elastalert2/discussions
Hi everyone, I have some problem with my alert config. I want to use alert_text_args to get nested field: log.Obj_ReponseCC.sendMessage.from But the problem is log.Obj_ReponseCC is full name of a field and elastalert think that Obj_ReponseCC is subfield of log field. How to fix this!!
This is full alert config:
This is JSON log: