Skip to content

Frequency rule #112

Locked Answered by jertel
pradeepgadkari asked this question in Q&A
May 5, 2021 · 1 comments · 1 reply
Discussion options

You must be logged in to vote

The rule appears formatted correctly. Is there any chance of a timezone mismatch? Or perhaps ElastAlert is pointing at the wrong Elasticsearch instance?

You could debug the problem by changing the index to "*" and switching from a term filter to a query_string filter of "*". Then, once you start getting hits, begin narrowing down the index and filter to help isolate the problem.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@pradeepgadkari
Comment options

Answer selected by pradeepgadkari
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants