Skip to content

Using aggregation_key and summary_table_fields, but the generated alerts are not displaying the table content #1530

Closed Answered by jertel
aisuhua asked this question in Q&A
Discussion options

You must be logged in to vote

It's not clear from the logs what's going on with your test. In one log file it's showing that all three events are being treated as a separate aggregation, even though two of them use "alice" as the username. It's unknown if there's a username vs username.keyword issue, or something is off in the raw event data itself (trailing spaces, etc).

Also, the debug alerter doesn't support rendering summary tables.

Replies: 3 comments 3 replies

Comment options

You must be logged in to vote
3 replies
@aisuhua
Comment options

@jertel
Comment options

@aisuhua
Comment options

Comment options

You must be logged in to vote
0 replies
Answer selected by aisuhua
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants