-
When using a blacklist rule, based on url, detection is correclty performed, but alerting doesn't work. Message The entry in my blacklist file is a typical URL like https://bidder.criteo.com/cdb
Any insight? |
Beta Was this translation helpful? Give feedback.
Answered by
jertel
Mar 16, 2024
Replies: 1 comment 2 replies
-
What do you mean when you say "detection is correctly performed"? From the stack trace above it looks like it failed to get into the detection logic. |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
The problem is most likely due to your data record in Elasticsearch containing a list value inside the field set as your compare_key. ElastAlert 2 is expecting a single value, not a list, to be in those records.