Alerts and Actions, Log Treshold, Field not found


I want to use the Alerts and Actions feature, to create a Log treshold alert on the field "cluster_state.status". Which is a standard field used to monitor the cluster status.
This field is not available in the dropdown.
How can I make this field available in the dropdown?

Hi @Debeste,

The reason for not seeing that field is that the "Log threshold alert" relies on the same indices used in Observability > Logs, and monitoring-es-* is not included in that list. If you really want to use this type of alert in that index, you can add it in Observability > Logs > Settings > Indices. Then, the alert will show all the fields contained in the .monitoring-es-* indices.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.