The problem is that now, when we receive the message body, we won't know from what host belongs the mount point. So we will need to look for it manually. Is there some approach to Create alert per more than one fields? For example, in this case, to create alert per mount point and agent hostname.
Something interesting would be to be able to select some values from the query as variable. For example:
{{alertName}} - {{context.group}} is in a state of {{context.alertState}} in {{agent.hostname}}
Reason:
{{context.reason}}
I tried with the latest version of Kibana (7.8.1) as well. Exactly the same behavior. I installed from the official repository which uses RPM packages. I am using red hat 7.8.
Seriously I am the only one I can not create alerts per multiple fields?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.