Skip to content

Help creating rule #1258

Closed Locked Answered by jertel
ngms17 asked this question in Q&A
Discussion options

You must be logged in to vote

Sounds like you need a frequency rule with a query_key: dest.ip setting: https://elastalert2.readthedocs.io/en/latest/ruletypes.html#frequency

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by jertel
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants