Two rules have the same context, but only one of them is firing an alert. #1280
-
Hi, in my ElastAlert rules folder, I have two rules with exactly the same meaning and syntax, only the names are different, and I got only one firing: rule1.yaml
and rule2.yaml
It only fires alert of the rule name '030d56aacc99ec79_b8ea32340e1f978c' when I expect it to fire both. Is that normal or abnormal, and why? P.S.: when I deleted the file 'rule1,' and the other rule is firing. :( |
Beta Was this translation helpful? Give feedback.
Answered by
jertel
Sep 25, 2023
Replies: 1 comment
-
Does the log show that it is loading both? If so, does the log show that both are running and making queries? Enable debug logging if necessary. |
Beta Was this translation helpful? Give feedback.
0 replies
Answer selected by
jertel
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Does the log show that it is loading both? If so, does the log show that both are running and making queries? Enable debug logging if necessary.