Thank you for this great support where we get reply in few minutes. We're very grateful to all of you guys.
We're using latest version of ELK. In alert and action > Log Threshold, less than feature doesn't work as highlighted in the screenshot
We're intended to get alert when a logsource stop sending logs, here if we change it with more than X number of logs entries then it works and trigger an alert but less than doesn't work.
Here are two observations:
1st observation, if logsource i.e host.name wp-pri stop sending logs then in realtime wp-pri will not be appearing in the realtime logs that's why my condition becomes false. It make sense.
But here I'm doing it like wp-pri hostname is appreaing in the real time logs. I know in last 30 minutes this hostname doesn't have more than 2000 json documents, it should have trigger an alert now. When I change it like if more than 1000 logs occur then it trigger an alert successfully.
Please help me what's happening here and how can I accomplish my goal.
Did you go to Discover set time range to 30 mins and filter on the host.name : "wp-pri" and type : "auditd" you get a count of less than 2000 if so the alert should fire or perhaps wrong in the logic.
Hmmm there is something interesting going on. It is late where I am at, I will need to take a look tomorrow and perhaps ask for some guidance.
The logic is not working as I understand it... we are trying to mix positive and negative logic.
It appears that perhaps since there are no / 0 documents that match the type and host.name conditions that those conditions are then false and since all the conditions are ANDed that the overall condition is false and thus the alert does not fire.
Your discover showed 0 documents matching... so I think that is what is happening.
I think if there were a couple documents that matched that perhaps the alert would fire.
I will do my best to check, or see if I can get someone else to take a look.
I did verify that if you filter on a term like host.name IS wp-pri and that filter results in 0 Documents you can not use GROUP BY host.name you can not group by the field that returns 0 results.
Can you please post / show your current / working / solution please we are interested.
The team actually created an issue related to your request if you want to take a look
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.