Skip to content

hive_alert_config title and description fields #339

Locked Answered by ferozsalam
shortstack asked this question in Q&A
Discussion options

You must be logged in to vote

Hi - excuse my brevity as I'm on a phone right now with no access to a computer for a few hours.

I will have to check about the title for certain when I'm behind a computer but you should be able to use the standard ElastAlert syntax, alert_subject and alert_subject_args as described at https://elastalert2.readthedocs.io/en/latest/ruletypes.html#alert-subject - you don't need to set a custom title in the hive_alert_config.

The description and (see my reply in thread below) tags can be templated by using the field values from the rule or the match directly - i.e. match[agent][hostname] should be templated as agent.hostname and rule[title] can be templated as title.

This matches how the ale…

Replies: 1 comment 3 replies

Comment options

You must be logged in to vote
3 replies
@shortstack
Comment options

@ferozsalam
Comment options

@shortstack
Comment options

Answer selected by shortstack
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants