Skip to content

MISSING VALUE in alert #353

Closed Locked Answered by mrfroggg
SerhiiZahuba asked this question in Q&A
Discussion options

You must be logged in to vote

I'm not using frequency type often, so I can be wrong, but I use a lot spike and flatline:

Not all field from ES are available when there is a match as it counts a number of documents and based on the query_key.

you are using include, this might be why "hostname" is included in there.

Work around: try to add more fields to include, but in my experience, include is useless with spike and flatline.
Or, add your needed fields to the query_key. This will make a unique match based from all those field contents, so be careful, it might affect your matches.

Other workaround, you are using a frequency of 1 event (num_events), what if you try a rule with the any type? All fields are available with a…

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by jertel
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants