Replies: 1 comment 2 replies
-
In Frequency rules, |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I have documents in ElasticSearch which contains at least 5 fields: solution, source, environment, region, level
And i have to get alert, when one of resulting group
solution*source*environment*region
contains 10+ documents withlevel:<4
My config:
But in alert i recieved the same num_matches (in test cases):
And when i manualy check documents, the counters per group not match with alerts.
What i missing? Can anyone help me to achieve results i need?
Beta Was this translation helpful? Give feedback.
All reactions