Closed bongmu closed 1 month ago
Multiple indexes are specified. When the "error" keyword appears in multiple indexes at the same time, only one is matched and then an alarm is sounded. What I want is to match multiple indexes at the same time and sound an alarm in sequence.
config:
es_host: xxx es_port: 9200 name: "dev-all-err"
type: "frequency" index: "xxx-,xxx-,xxx-,xxx-" is_enabled: true
filter:
num_events: 1
timeframe: minutes: 1
realert: minutes: 1
timestamp_field: "@timestamp" timestamp_type: "iso" use_strftime_index: true include: ["tags", "message", "@timestamp"]
alert_text_type: alert_text_only alert_text: | xxx
alert:
See #11
Multiple indexes are specified. When the "error" keyword appears in multiple indexes at the same time, only one is matched and then an alarm is sounded. What I want is to match multiple indexes at the same time and sound an alarm in sequence.
config:
es_host: xxx es_port: 9200 name: "dev-all-err"
type: "frequency" index: "xxx-,xxx-,xxx-,xxx-" is_enabled: true
filter:
num_events: 1
timeframe: minutes: 1
realert: minutes: 1
timestamp_field: "@timestamp" timestamp_type: "iso" use_strftime_index: true include: ["tags", "message", "@timestamp"]
alert_text_type: alert_text_only alert_text: | xxx
alert: