-
Hi everyone, Sorry to bother y'all. I had a quick question regarding Elastalert and the .monitoring indexes.
I'm assuming it has to do with the Thanks for your time Edit: |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
There is nothing in ElastAlert 2 that prevents access to hidden indexes (indexes that begin with a period). Below is my debug log output from querying the hidden .kibana* indices:
And the rule file I used:
and the relevant portion of my config:
And the alerted record as seen in Kibana: I suggest broadening the index value in the rule yaml to Also, note the following warning logged out by Elasticsearch's driver:
Perhaps you're using a newer Elastic version that has disabled API access to the hidden indices. My test above is using 8.7.1. |
Beta Was this translation helpful? Give feedback.
There is nothing in ElastAlert 2 that prevents access to hidden indexes (indexes that begin with a period). Below is my debug log output from querying the hidden .kibana* indices: