You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
When the first event_src stop to send logs, an alert is raised.
But , when a another event_src stop to send log (i.e five minutes later), no alert is raised.
The buckets (two for my test) are well seen by elastalert. elastalert see the two buckets at the beginning, then he notice the first missing bucket, and finally the second (two bucket -> one bucket -> zero bucket)
Now, the strange thing : I tested the same alert on elastalert v0.0.93 (ES version is also 2.4.2) and it works fine : one alert when the first event_src stop to send logs and another one when the second event_src stop to send logs.
With elastalert v0.0.93 ,it seems that realert is not working as I don't have any other alert than the first two alerts .
With elastalert v0.1.12, it seems that realert is working well as I have new alerts every five minutes
So, I would suspect a bug in v0.1.12 around flatline and use_temrs_query but I'm asking if somebody else has noticed the same behavior as the issue could be due to my own specific environment
(without use_terms_query, alert is fine but I have to use use_terms_query for performance reasons)
Thanks for your feedback ! :-)
The text was updated successfully, but these errors were encountered:
Hello everybody,
ES version : 2.4.2
After have upgraded from elastalert v0.0.93 to elastalert v0.1.12, the following alert fail :
When the first event_src stop to send logs, an alert is raised.
But , when a another event_src stop to send log (i.e five minutes later), no alert is raised.
The buckets (two for my test) are well seen by elastalert. elastalert see the two buckets at the beginning, then he notice the first missing bucket, and finally the second (two bucket -> one bucket -> zero bucket)
Now, the strange thing : I tested the same alert on elastalert v0.0.93 (ES version is also 2.4.2) and it works fine : one alert when the first event_src stop to send logs and another one when the second event_src stop to send logs.
With elastalert v0.0.93 ,it seems that realert is not working as I don't have any other alert than the first two alerts .
With elastalert v0.1.12, it seems that realert is working well as I have new alerts every five minutes
So, I would suspect a bug in v0.1.12 around flatline and use_temrs_query but I'm asking if somebody else has noticed the same behavior as the issue could be due to my own specific environment
(without use_terms_query, alert is fine but I have to use use_terms_query for performance reasons)
Thanks for your feedback ! :-)
The text was updated successfully, but these errors were encountered: