Cannot get flatline rule to work, please help #452
-
Hello all, I am having an issue with a flatline rule. Testing the rule works fine, but then when I run elastalert with this rule - it doesn't trigger any alerts. Please see below the configuration files and the run outputs:
|
Beta Was this translation helpful? Give feedback.
Replies: 3 comments 2 replies
-
also, for some reason, elastalert-test-rule actually finds 4 matches, not one.. hmm |
Beta Was this translation helpful? Give feedback.
-
Putting timeframe lower than 50 minutes makes elastalert-test-rule not to see any matches too. I must be missing something... |
Beta Was this translation helpful? Give feedback.
-
Your logs from the Without knowing what documents exist and at what times it's difficult to troubleshoot. When you search the I suggest trimming back your frequency to 30 seconds to make it easier to troubleshoot, and then enable debug logging, and possibly es trace logging. The documentation for elastalert2 explains how to do this. |
Beta Was this translation helpful? Give feedback.
Your logs from the
elastalert
command only show 4 minutes of log data, but you are using a frequency of 50 or 60 minutes. So I have to assume you are not getting alerts even after 50 or 60 minutes either. Is that true? You have to let the app run for the full frequency duration before you will see alerts.Without knowing what documents exist and at what times it's difficult to troubleshoot. When you search the
default_test
forrobotName: robot
in Kibana, are there any hits? If so, how often are they?I suggest trimming back your frequency to 30 seconds to make it easier to troubleshoot, and then enable debug logging, and possibly es trace logging. The documentation for elastalert2 explain…