Skip to content

Having issues with summary_table_fields #1060

Closed Locked Answered by jertel
dakotacody asked this question in Q&A
Discussion options

You must be logged in to vote

Is there a summary_table_max_rows defined in your ElastAlert2 config file? (Let's rule out the simple explanation first)

I would recommend enabling debug so you can look at the true number of matches being returned by Elasticsearch. If you see multiple records being returned by your rule query but only one row shows up in the summary table then that will tell you the problem is not with your query or with Elasticsearch, but with the summary table rendering logic in ElastAlert 2. If you only see one record returned then you will know to focus on your query, aggregation window, or Elasticsearch server settings.

Replies: 1 comment 4 replies

Comment options

You must be logged in to vote
4 replies
@dakotacody
Comment options

@dakotacody
Comment options

@jertel
Comment options

@dakotacody
Comment options

Answer selected by jertel
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants