bitsensor / elastalert-kibana-plugin

ElastAlert Kibana Plugin
https://bitsensor.io/blog/elastalert-kibana-plugin-centralized-logging-with-integrated-alerting
Other
556 stars 118 forks source link

Wrong alarms posting to Slack #150

Open Ignacivs opened 4 years ago

Ignacivs commented 4 years ago

Greetings, we are having an issue with this plugin. Only one of our Alarms displays correctly, even thou all of the other alarms have the same query as this heatmap has.

Heatmap https://imgur.com/a/2w6wWzH

The one the working as intended one https://i.imgur.com/nD9vcWF.png

This is one of the non working ones: https://i.imgur.com/qOTu8My.png

Thing that was also happening is that we had event.warning.captured>0 OR event.warning.confirmed>0 OR event.warning.vikingSalesRegistrationSent>0 OR event.warning.vikingSalesRegistrationSent>0 trigger when only event.status.vikingDepositRegistrationSent.error:* was supposed to trigger. I have checked and the web-hooks are correct for all 3 of them.

We are using Kibana 7.5.0