I tried to create a rule using custom threshold to write to an index for the alert action.
Running 8.13.
I created the index, and mappings ahead of time
I added the connector + the index
I tested the rule by going below the threshold, I see the alert triggers in the rule (But the index never gets populated) Contents of action trigger here:
I upgraded to 8.18. same problem.
The only thing that seems to work is setting the alert action frequency from "For each alert - on status changes" to "Summary of alerts - on check intervals"
But this will just keep sending an alert to the index if the alert is triggered.
I don't want that.
I want just one alert sent to the index if the alert happens. And once its resolved send another alert.
Does anyone else have this issue? Am I the only one?
Can anyone help please?
I created a ticket for this on Kibana github, a while back. I just updated the post here
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.