Can top_count_keys be passed to http_post_payload values? #146
-
Hi, Just wondering if I can use the result of
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 1 reply
-
If top_count_keys is not the item of the target index, I think it is useless.
|
Beta Was this translation helpful? Give feedback.
-
When you specify Disclaimer: I've not used http_post alerts, nor top_count_keys. So take the above worth a grain of salt. All I'm going off of here is a quick skim through the code. |
Beta Was this translation helpful? Give feedback.
When you specify
top_count_keys
in the rule, ES will respond back with a mapping of the top 5 hostnames and how many times that appeared in the rule match. That mapping of hostnames to counts will be stored into a match key calledtop_events_hostname
. Based on that, in your example, if you replacehosts: top_count_keys
withhosts:top_events_hostname
perhaps you might get a dictionary of hosts to counts posted to your URL. I've not attempted to do this so it might not work at all.Disclaimer: I've not used http_post alerts, nor top_count_keys. So take the above worth a grain of salt. All I'm going off of here is a quick skim through the code.