If we go in the rules and select rule as elasticsearch query.
Can we do an aggregation in the elasticsearch query.
Kibana Rules does not yet fully support all Elasticsearch aggregations (follow the GitHub issue here: Elasticsearch Query Stack Alert Aggregation Support · Issue #95161 · elastic/kibana · GitHub).
It seems like v8.7 added support at least for a
terms aggregation, however
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.