Closed jmacdone closed 9 months ago
It's an issue, not a pull request. Please submit a pull request.
I don't see an issue with this approach if you do want to submit a proper PR with all the requirements. I'm converting this issue into a Discussion since it doesn't represent a bug in the project, but more represents a discussion around a potential enhancement.
I didn't tick all the boxes for a proper PR, but see: https://github.com/jmacdone/elastalert2/commit/38b7c1f41d60201764e3c575437f7abbc788ac1d
In short, I'm using
logstash-%Y.%m.%d.%H
(i.e. hourly indexes), but the format_index is only tuned for daily indexes (the default for logstash). This checks for%H
in the index pattern and changes to using ahours=1
timedetla. Better way?