Skip to content

Elastalert scan all the documents in new timeframe? #1502

Answered by jertel
ishukeshri2712 asked this question in Q&A
Discussion options

You must be logged in to vote

Are you asking if ElastAlert 2 will find a backdated log that was ingested with a timestamp value earlier than the last ElastAlert 2 query? If so then that depends on the rule configuration. I suggest looking at elastalert.py::set_starttime() to see all nuances involved.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by jertel
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants