Open xiahuhu1 opened 3 years ago
See _'No mapping found for [alerttime] in order to sort on', it means something went wrong when elastalert creating index (likely caused by previous elastalert start failure). Just delete the existing elastalert_* indices auto created by elastalert in your elasticsearch cluster and restart elastalert.
Version Info
kibana version: 7.9.0
elasticsearch: 7.9.0
elastalert: 3.0.0-beta.0
Docker Run
Config.json
Elastalert.yaml
I've revised the elastalert.yaml file:
Error logs
And the elasticsearch server is normal,Please tell me how to solve this problem.
Looking forward to your reply,thanks!!