Skip to content

Rules defining #210

Locked Answered by jertel
Raksniru asked this question in Q&A
Jun 2, 2021 · 1 comments · 15 replies
Discussion options

You must be logged in to vote

I suggest enabling debug on ElastAlert 2, this will give you more information on what's going on. Also remove all queries except for the one you know should match, to simplify your rule while you troubleshoot. Once you get it working you can slowly add back more complexity to your rule to find out what's breaking it.

Replies: 1 comment 15 replies

Comment options

You must be logged in to vote
15 replies
@Raksniru
Comment options

@Raksniru
Comment options

@nsano-rururu
Comment options

@Raksniru
Comment options

@Raksniru
Comment options

Answer selected by jertel
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants