Skip to content

Rule not triggering alerts but does with elastalert-test-rule --alert #1363

Locked Answered by jertel
iliketurtlesyep asked this question in Q&A
Discussion options

You must be logged in to vote

The queries look identical, and assuming you are redacting the identical Elastic hostname, using the same ElastAlert 2 config (Elast user/pass), and using the same ElastAlert 2 code (both modes are running from the same server, using the same ElastAlert 2 version) then it doesn't seem possible for one query by host.hostname to work, but the other not to work.

I think my next step would be to start narrowing down if I can get any hits via a hostname query. Ex: host.hostname: ip*, host.hostname: *, _exists_: host.hostname, etc.

Replies: 2 comments 12 replies

Comment options

You must be logged in to vote
9 replies
@jertel
Comment options

@jertel
Comment options

@iliketurtlesyep
Comment options

@iliketurtlesyep
Comment options

@jertel
Comment options

Comment options

You must be logged in to vote
3 replies
@jertel
Comment options

Answer selected by jertel
@iliketurtlesyep
Comment options

@jertel
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants