I have several messages that are ingested together and have same "batchId" field. I need to check a condition (simple calculation), based on two fields from messages that have the same "batchId" (and couple of more fields).
How do I create such alert? Experimented with aggregations and buckets, but can't nail it.
Thank you in advance!