Skip to content

Flatline alerts generating false negative alerts #1440

Closed Locked Answered by jertel
eeH9ahso asked this question in Q&A
Discussion options

You must be logged in to vote

It looks like ElastAlert 2 is functioning correctly, but the query to Elasticsearch isn't returning anything. Perhaps you have ElastAlert 2 pointed at the wrong ES cluster? Or there's a mistake in your datastream configuration, where it's not pulling from that index? Perhaps try setting the rule's index property to bypass the datastream and query the backing index directly.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by jertel
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants