Skip to content

Metadata in Alert Rule #1368

Closed Locked Answered by jertel
MateSousa asked this question in Q&A
Discussion options

You must be logged in to vote

Yes, it's possible. Ex:

name: any_test
type: any
index: "*"
alert: command
command: 
  - echo 
  - "*** Hello, this is the time: {@timestamp}"

output:

2024-01-30 21:36:29,288     INFO           elastalert Alert sent to Command
*** Hello, this is the time: 2024-01-31T02:21:54.157771Z
2024-01-30 21:36:29,301    DEBUG urllib3.connectionpool http://127.0.0.1:9200 "POST /elastalert/_doc HTTP/1.1" 201 164

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by MateSousa
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants