Replies: 1 comment 8 replies
-
Did you read the source code? |
Beta Was this translation helpful? Give feedback.
8 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Good day everyone.
Looking for some understanding of elastalert_error index mapping.
The index keeps the failed rule name under data.name.
The mapping is:
which AFAIK means that there is no way to search by failed index name.
What is the reason for this mapping and is it possible to change it in the elastalert configuration?
Thanks
Beta Was this translation helpful? Give feedback.
All reactions