Skip to content

How to display match_body in the elastalert metadata with writeback index? #1602

Answered by vutuong
vutuong asked this question in Q&A
Discussion options

You must be logged in to vote

@jertel I want to enable match_body in the Elasticsearch mapping to display and query it with Grafana. My workaround is to rebuild the container image and replace the es_mapping file from https://github.com/jertel/elastalert2/tree/master/elastalert/es_mappings with a new mapping that enables match_body.
I have one more question: What does match_time in in the meta_data? What is difference between match_time and alert_time?
I can not find it in the doc at: https://elastalert2.readthedocs.io/en/latest/elastalert_status.html

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@jertel
Comment options

Answer selected by vutuong
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants