Realert does not seems to be taking effect? #1308
-
I am using the flatline rule type to monitor the ELK indexes for any data drops. I am trying out the flatline with threshold = 1, timeframe = 10 minutes, ie. ElastAlert2 will alert me once there is zero log entry within last 10 minutes. Elastalert will scrap off data every , with run_every = 1 minute in the config.yaml. However, it turns out ElastAlert2 keeps sending me an alert every minute for same match every minute? `name: "Nodata flatline - Infoblox"
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 4 replies
-
Perhaps the |
Beta Was this translation helpful? Give feedback.
If a rule encounters an error while sending an alert, it will consider the alert to not have been sent. Since the error is from JIRA, and the rule name matches the picture you included, that tells me that the error is causing the repeated alerts. I know you stated to disregard the JIRA error but I can't disregard it since it's tied to the same rule for which you're asking for help.