I am creating my custom rule to monitor the filebeat-* events to monitor login events only between 09:00 to 20:00. And needs to send an alert if any event happens after the said period. Can we do that with custom rules?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.