Skip to content

Invalid multiple indexes specified #1464

Closed Locked Answered by jertel
bongmu asked this question in Q&A
Discussion options

You must be logged in to vote

By attempting to combine them into a single rule it causes the re-alert to prevent the second event from alerting. So if you are suggesting that both indices receive an event at the same time, and you want both alerts to be sent then you have two options:

  1. Simplest: Use two different rules, each using its own index.
  2. Define the _index field as a query key. I've not tried this but perhaps it could work.

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@bongmu
Comment options

@jertel
Comment options

Answer selected by jertel
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants