Skip to content

Get raw logs/documents of an event firing alert when use_terms_query #1219

Locked Answered by jertel
eveningcafe asked this question in Q&A
Discussion options

You must be logged in to vote

Is this a limitation of "use_term_query"?

Yes, it is, because performing an aggregate query against elasticsearch results in only counts of each aggregation returned.

Can we create an if condition to re-query Elasticsearch a second time to get the raw log?

ElastAlert 2 doesn't support a concept of follow-up queries. However, the Enhancements feature allows developers to add small Python scripts during the alerting phase, which could perform additional queries if coded to do so. A similar request was discussed in #1207.

In my system, Elasticsearch is strong, but ElastAlert's performance is a concern when it can't run in HA (High Availability) mode.

I don't understand this statement. …

Replies: 4 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by jertel
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants