Skip to content

How does num_event:0 works? #1500

Closed Answered by jertel
ManitejaDev asked this question in Q&A
Jul 17, 2024 · 1 comments · 3 replies
Discussion options

You must be logged in to vote

Flatline was added as an extension of Frequency rule to handle the alerting due to lack of logs. You are asking if Frequency can alert on a lack of logs and that is not supported. Using a num_events: 0 might see some specific scenario where it does send an alert but most situations will not work. Ex: Using a long timeframe where a prev run found some logs (alert) and the next query finds no logs and is able to alert again, using the previously found record as the alert data. But it's untested, unsupported, and not recommended.

Replies: 1 comment 3 replies

Comment options

You must be logged in to vote
3 replies
@jertel
Comment options

@ManitejaDev
Comment options

@jertel
Comment options

Answer selected by jertel
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants