Customize Kibana Alerting Rule

Hello,

Is there a way to customize the canned alert rules in Elastic Cloud > rules? (KQL Query?)

Frozen node is using disk cache and always at 90% and I would like to filter the node role. I tried some KQL expression in the filter box but it is not breaking as expected.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.