Skip to content

Using replicaCount: 2 in Helm chart sends all alerts twice #451

Closed Locked Answered by ferozsalam
tsboris asked this question in Q&A
Discussion options

You must be logged in to vote

I will defer to @jertel's opinion on this, but my understanding of the way ElastAlert works suggests that it does not currently support multiple replicas working in tandem.

ElastAlert simply runs in a loop, with an instance maintaining a queue of rules to be run and writing its current search status back to an index within Elasticsearch. Multiple replicas would have no knowledge of each other and would therefore have no way of preventing race conditions.

A similar question from some time ago with a reply from the original chief contributor suggests that a single instance is all that is supported, with no concept of coordination between instances.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by tsboris
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants