Is it possible to create either an alert or a watcher, that is based off the count of a specific field.
I currently have application logs that ingest into elasticsearch. I then have a timelion graph that graphs the count of the field 'message_code:200'. This is good to see visual changes, but requires someone to visually see it.
Based off this, I want to create an email alert that notifies me if the count reaches over a certain threshold (eg: 500 count).
This seems pretty simple but I can't seem to find which Alert i should use. An index Threshold seems the way to go, but I can't pick a specific field to count on.
Running Kibana and Elasticsearch 7.9.0