Skip to content

Getting number of hits for each unique query_key #1176

Closed Locked Answered by jertel
RezaBagheri3 asked this question in Q&A
Discussion options

You must be logged in to vote

Unfortunately, the counts per query_key are not currently made available to the alerters.

timeframe: Setting to 10 minutes instructs the rules to only include records that fall within the past 10 minutes.
buffer_time: Setting to 10 minutes instructs ElastAlert 2 to query from 10m ago till present.
run_every: Setting to 10 seconds instructs ElastAlert 2 to run the rule every 10 seconds.

Therefore, your rule will query Elasticsearch every 10 seconds and each query will overlap the previous query time window by 9m 50s. For each result in the query, ElastAlert 2 will compare the @timestamp on the result with the timerange. If it's within 10m then it will add it to the match set, which is reme…

Replies: 1 comment 4 replies

Comment options

You must be logged in to vote
4 replies
@RezaBagheri3
Comment options

@david-sykora
Comment options

@jertel
Comment options

@nsano-rururu
Comment options

Answer selected by RezaBagheri3
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
4 participants