Skip to content

Elastalert for logs ingested to ElasticSearch cluster per day that is size? #1496

Answered by jertel
ishukeshri2712 asked this question in Q&A
Discussion options

You must be logged in to vote

Consider an any type rule with no filter that runs once a day and has use_count_query: true. You might then have access to num_hits as a var in your alert message. I haven't tried this, so you'll need to read the docs and play with it to see what happens.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by jertel
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants