-
Hello! I recently encountered an issue where I deleted a rule without disabling it first.... I read later the documentation and also this post. So, I am in this scenario where I deleted it and the alerts keep arriving. How can I restore this rule or ensure it is fully deleted from ElastAlert? If I copy the rule again with the same I have other scenarios where I deleted rules without disabling and did not receive any more alerts or notices in the ElastAlert indexes. I thought that maybe this new issue with the alerts might be because the rule has I am quite lost here... has anybody encountered with something similar? Thank you for your assistance! Update: Problem Timeline: Made an update and changed it to: Kept receiving alerts with the name "My Flatline Alert". Also, noticed on index, that "another rule" called: MyFlatlineAlert was constinously Pausing. (it was like two instances of the same rule with different names) Deleted the rule without disabling. But I keep receiving alerts with "My Flatline Alert" hahaha. I understand that the alert with the name "My Flatline Alert" stayed in memory, but i want it to make it dissapear 😂 pls help me |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 1 reply
-
I just deleted a rule with a limit_execution and it successfully removed the scheduled job and the rule from memory.
Notice the log lines that states the scheduler removed the job. The rule did not fire after that. Restarting ElastAlert 2 to clear out the rule is the way forward. I can't recommend an alternative approach with any confidence, since I don't know how your rule got into this state. E.g., I can't seem to reproduce it. |
Beta Was this translation helpful? Give feedback.
-
Hi again! So I come with bad news (for me haha) I reproduced locally the scenario I described, long story short for whoever reads this: Do not change ever the name of the rule, if you want to do it, create it with a different name both the file and the my rule config:
Started with my rule file On the same rule file, updated the
I deleted the file rule
Added again the file
Not even that stopped the rule from querying, I still receive the alerts... I see the "existing job", is the one I can't disable! hahaha So nothing else to do here but Today I learned something new about ElastAlert haha, thanks for your time Jertel! |
Beta Was this translation helpful? Give feedback.
I just deleted a rule with a limit_execution and it successfully removed the scheduled job and the rule from memory.