Skip to content

Alerting issue with url-based blacklist #1394

Closed Locked Answered by jertel
gatrene asked this question in Q&A
Discussion options

You must be logged in to vote

The problem is most likely due to your data record in Elasticsearch containing a list value inside the field set as your compare_key. ElastAlert 2 is expecting a single value, not a list, to be in those records.

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@gatrene
Comment options

@jertel
Comment options

Answer selected by jertel
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants