Skip to content

How to write the alarm rules I need? #1142

Locked Answered by jertel
netkey asked this question in Q&A
Discussion options

You must be logged in to vote

ElastAlert 2 can handle percentage matches, where a secondary filter count is divided by a primary filter count, and alerts when that ratio exceeds a set threshold. But I don't believe there is a way to have it perform a count of unique items. That would look more like a hybrid of the cardinality and percentage match rule types, which does not currently exist. If you'd like to submit a PR to the project with such a rule type, I'm open to it.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by jertel
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants