Skip to content

Queries regarding functioning of elastalert2 #1504

Closed Locked Answered by jertel
ishukeshri2712 asked this question in Q&A
Discussion options

You must be logged in to vote

I'm having trouble understanding these questions. Did you read the documentation and all of the parameters related to timing?

ElastAlert 2 requires records to have a timestamp field.

run_every values depend on each user's use case. Same with buffer_time.

I recommend (re) reading the documentation because these topics are explained in that documentation.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@jertel
Comment options

Answer selected by ishukeshri2712
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants