-
hello,I need to implement an alert, but found that none of the existing rule types seem to meet my needs. My needs are as follows: Index: client-log-* How should I write this rule? |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
ElastAlert 2 can handle percentage matches, where a secondary filter count is divided by a primary filter count, and alerts when that ratio exceeds a set threshold. But I don't believe there is a way to have it perform a count of unique items. That would look more like a hybrid of the cardinality and percentage match rule types, which does not currently exist. If you'd like to submit a PR to the project with such a rule type, I'm open to it. |
Beta Was this translation helpful? Give feedback.
ElastAlert 2 can handle percentage matches, where a secondary filter count is divided by a primary filter count, and alerts when that ratio exceeds a set threshold. But I don't believe there is a way to have it perform a count of unique items. That would look more like a hybrid of the cardinality and percentage match rule types, which does not currently exist. If you'd like to submit a PR to the project with such a rule type, I'm open to it.