"condition" part example

I am pretty new using Watcher. I saw some examples but I couldn't find what I wanted.

I have query like:
layers.arp.arp_arp_src_hw_mac:"00:b6:44:11:3a:61" or _index

I want to generate an alarm every time this mac is plugged into a query.What like condition should I write?

Have a nice day.

It sounds like you're trying to create an alert based on queries that are being sent to Elasticsearch- I'm not sure that kind of trigger is supported.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.