-
Hi everyone! I'm encountering an issue with my flatline rule setup and would appreciate any guidance or suggestions you might have. Is there a way to configure EA to account for potential delays in log arrival? This is the scenario: In my global config I have set The problem is, that we consider that alert to be a "false alert" because the logs did arrived, late but arrived. Is there a way to configure the rule to account for potential delays in log arrival and to prevent alerts until a certain waiting period has passed??? Is for this case a Thanks for your help!! |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
|
Beta Was this translation helpful? Give feedback.
query_delay
might help with this situation: https://elastalert2.readthedocs.io/en/latest/ruletypes.html#query-delay