MISSING VALUE in alert #353
-
Hello. I have this rule in my config
but in lert i see |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments
-
I'm not using Not all field from ES are available when there is a match as it counts a number of documents and based on the query_key. you are using Work around: try to add more fields to include, but in my experience, include is useless with spike and flatline. Other workaround, you are using a frequency of 1 event (num_events), what if you try a rule with the |
Beta Was this translation helpful? Give feedback.
-
Sorry I had a configuration error. Everything is already working. |
Beta Was this translation helpful? Give feedback.
I'm not using
frequency
type often, so I can be wrong, but I use a lotspike
andflatline
:Not all field from ES are available when there is a match as it counts a number of documents and based on the query_key.
you are using
include
, this might be why "hostname" is included in there.Work around: try to add more fields to include, but in my experience, include is useless with spike and flatline.
Or, add your needed fields to the query_key. This will make a unique match based from all those field contents, so be careful, it might affect your matches.
Other workaround, you are using a frequency of 1 event (num_events), what if you try a rule with the
any
type? All fields are available witha…