How to Include Mutliple Lines in Elastalaert Rules File #207
Replies: 1 comment 12 replies
-
If you have any questions about bitsensor/elastalert, please check with the developer. |
Beta Was this translation helpful? Give feedback.
12 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hi All,
This is the elastalert container logs when using json file as logging driver.
The same type of error logs elastalert container when using logging driver as syslog
Above both log are pretty much same one log elastalert container(Or could be any container log like postgres, mysql etc) except that when i use syslog as logging driver that log is coming in multiple lines.
So if used elastalert any rule with query parameter as exception(it could be any keyword that we want to capture) for message field, i get only line of error(filter) log not all lines(stacktrace of that log) in my elastalert email/slack alert.
This type of email is coming in email alert
So how include all lines of that particular filer error/exception log in elastalert email/slack alert.
Beta Was this translation helpful? Give feedback.
All reactions