I'm trying to configure an alert that when certain word is found, email is sent. Email connector is configured and test email works. My rule looks like this:
{
"query":{
"match" : {
"message": "client unexpectedly closed TCP connection"
}
}
}
When I click "Test query" button, it will find documents
"Query matched 258 documents in the last 3h."
I've scheduled to run query every 5 minutes.
Action is to use Email connector.
Action frequency: For each alert = On check intervals
Run when: Query matched
If alert matches a query option is selected. I wonder what "a customer query is required" warning means! Custom query is defined earlier!!
Then there is email address, subject and message
I can see that rule runs fine, but ít doesn't generate any alerts