Skip to content

Rules not triggered until timepart of --start and/or --end is changed #1378

Closed Locked Answered by jertel
litsegaard asked this question in Q&A
Discussion options

You must be logged in to vote

ElastAlert 2 records the previous run time for a rule so that the next run doesn't re-query the same records. So if your newly re-indexed data is occupying the same time frames as a previous rule run then that would explain it. You stated that you are tweaking the start/end times but without specific examples and their corresponding logs this is the best explanation I can give you.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by jertel
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants