Why some of the alert rules stop retrieving? #1256
-
Beta Was this translation helpful? Give feedback.
Answered by
jertel
Aug 25, 2023
Replies: 1 comment
-
There's not enough of the log included for me to understand what happened to ElastAlert 2 after the connection problem. If you are stating that the entire ElastAlert 2 application ceased to function then I will need those logs. However, the discussion title suggests that only the single rule is not longer firing. ElastAlert 2 will auto disable failed rules. This behavior can be disabled if desired. |
Beta Was this translation helpful? Give feedback.
0 replies
Answer selected by
userzhangqg
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
There's not enough of the log included for me to understand what happened to ElastAlert 2 after the connection problem. If you are stating that the entire ElastAlert 2 application ceased to function then I will need those logs.
However, the discussion title suggests that only the single rule is not longer firing. ElastAlert 2 will auto disable failed rules. This behavior can be disabled if desired.