# Elastalert send me 0 hit query doesn't work ? please help

**URL:** <https://discuss.elastic.co/t/elastalert-send-me-0-hit-query-doesnt-work-please-help/283732>\
**Category:** Kibana\
**Created:** [September 9, 2021, 5:31am UTC](https://discuss.elastic.co/t/elastalert-send-me-0-hit-query-doesnt-work-please-help/283732 "2021-09-09T05:31:36Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Salim\_Adnan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/salim_adnan/32/76864_2.png) [@Salim\_Adnan](https://discuss.elastic.co/u/Salim_Adnan)\
**Post date:** [September 9, 2021, 5:31am UTC](https://discuss.elastic.co/t/elastalert-send-me-0-hit-query-doesnt-work-please-help/283732/1 "2021-09-09T05:31:37Z")

</div>

--------------my config.yaml------------

# This is the folder that contains the rule yaml files

# Any .yaml file will be loaded as a rule

rules\_folder: example\_rules

# How often ElastAlert will query Elasticsearch

# The unit can be anything from weeks to seconds

run\_every:  
minutes: 1

# ElastAlert will buffer results from the most recent

# period of time, in case some log sources are not in real time

buffer\_time:  
minutes: 15

# The Elasticsearch hostname for metadata writeback

# Note that every rule can have its own Elasticsearch host

es\_host: 192.168.3.98

# The Elasticsearch port

es\_port: 9200

# The AWS region to use. Set this when using AWS-managed elasticsearch

#aws\_region: us-east-1

# The AWS profile to use. Use this if you are using an aws-cli profile.

# See [Getting started with the AWS CLI - AWS Command Line Interface](http://docs.aws.amazon.com/cli/latest/userguide/cli-chap-getting-started.html)

# for details

#profile: test

# Optional URL prefix for Elasticsearch

#es\_url\_prefix: elasticsearch

# Connect with TLS to Elasticsearch

use\_ssl: true

#Verify TLS certificates  
#verify\_certs: false

# GET request with body is the default option for Elasticsearch.

# If it fails for some reason, you can pass 'GET', 'POST' or 'source'.

# See [http://elasticsearch-py.readthedocs.io/en/master/connection.html?highlight=send\_get\_body\_as#transport](http://elasticsearch-py.readthedocs.io/en/master/connection.html?highlight=send_get_body_as#transport)

# for details

#es\_send\_get\_body\_as: GET

# Option basic-auth username and password for Elasticsearch

es\_username: elastic  
es\_password: Mypasword

# Use SSL authentication with client certificates client\_cert must be

# a pem file containing both cert and key for client

verify\_certs: true  
ca\_certs: /etc/ca-certificates/ca.crt  
#client\_cert: /path/to/client\_cert.pem  
#client\_key: /home/aspire/master/master.key

# The index on es\_host which is used for metadata storage

# This can be a unmapped index, but it is recommended that you run

# elastalert-create-index to set a mapping

writeback\_index: elastalert\_status  
writeback\_alias: elastalert\_alerts

# If an alert fails for some reason, ElastAlert will retry

# sending the alert until this time period has elapsed

alert\_time\_limit:  
days: 2

```
           -------- my rules--------

```

--lnx\_file\_or\_folder\_permissions.yaml--

name: file\_or\_folder\_permissions\_change\_0  
description: Detects file and folder permission changes  
index: auditbeat-\*  
priority: 4  
realert:  
minutes: 0  
filter:

- query\_string:  
query: (a0:( _chmod_ OR _chown_ ) AND type:"EXECVE")  
type: any  
alert:
- debug

-------result show--------  
elastalert-test-rule --config config.yaml example\_rules/lnx\_file\_or\_folder\_permissions.yaml

INFO:elastalert:Note: In debug mode, alerts will be logged to console but NOT actually sent.  
To send them but remain verbose, use --verbose instead.  
Didn't get any results.  
INFO:elastalert:Note: In debug mode, alerts will be logged to console but NOT actually sent.  
To send them but remain verbose, use --verbose instead.  
1 rules loaded  
INFO:apscheduler.scheduler:Adding job tentatively -- it will be properly scheduled when the scheduler starts  
INFO:elastalert:Queried rule file\_or\_folder\_permissions\_change\_0 from 2021-09-08 11:14 +06 to 2021-09-08 11:29 +06: 0 / 0 hits  
INFO:elastalert:Queried rule file\_or\_folder\_permissions\_change\_0 from 2021-09-08 11:29 +06 to 2021-09-08 11:44 +06: 0 / 0 hits  
INFO:elastalert:Queried rule file\_or\_folder\_permissions\_change\_0 from 2021-09-08 11:44 +06 to 2021-09-08 11:59 +06: 0 / 0 hits  
INFO:elastalert:Queried rule file\_or\_folder\_permissions\_change\_0 from 2021-09-08 11:59 +06 to 2021-09-08 12:14 +06: 0 / 0 hits  
INFO:elastalert:Queried rule file\_or\_folder\_permissions\_change\_0 from 2021-09-08 12:14 +06 to 2021-09-08 12:29 +06: 0 / 0 hits  
INFO:elastalert:Queried rule file\_or\_folder\_permissions\_change\_0 from 2021-09-08 12:29 +06 to 2021-09-08 12:44 +06: 0 / 0 hits  
INFO:elastalert:Queried rule file\_or\_folder\_permissions\_change\_0 from 2021-09-08 12:44 +06 to 2021-09-08 12:59 +06: 0 / 0 hits  
INFO:elastalert:Queried rule file\_or\_folder\_permissions\_change\_0 from 2021-09-08 12:59 +06 to 2021-09-08 13:14 +06: 0 / 0 hits  
INFO:elastalert:Queried rule file\_or\_folder\_permissions\_change\_0 from 2021-09-08 13:14 +06 to 2021-09-08 13:29 +06: 0 / 0 hits  
INFO:elastalert:Queried rule file\_or\_folder\_permissions\_change\_0 from 2021-09-08 13:29 +06 to 2021-09-08 13:44 +06: 0 / 0 hits  
INFO:elastalert:Queried rule file\_or\_folder\_permissions\_change\_0 from 2021-09-08 13:44 +06 to 2021-09-08 13:59 +06: 0 / 0 hits  
INFO:elastalert:Queried rule file\_or\_folder\_permissions\_change\_0 from 2021-09-08 13:59 +06 to 2021-09-08 14:14 +06: 0 / 0 hits  
INFO:elastalert:Queried rule file\_or\_folder\_permissions\_change\_0 from 2021-09-08 14:14 +06 to 2021-09-08 14:29 +06: 0 / 0 hits  
INFO:elastalert:Queried rule file\_or\_folder\_permissions\_change\_0 from 2021-09-08 14:29 +06 to 2021-09-08 14:44 +06: 0 / 0 hits  
INFO:elastalert:Queried rule file\_or\_folder\_permissions\_change\_0 from 2021-09-08 14:44 +06 to 2021-09-08 14:59 +06: 0 / 0 hits  
INFO:elastalert:Queried rule file\_or\_folder\_permissions\_change\_0 from 2021-09-08 14:59 +06 to 2021-09-08 15:14 +06: 0 / 0 hits  
INFO:elastalert:Queried rule file\_or\_folder\_permissions\_change\_0 from 2021-09-08 15:14 +06 to 2021-09-08 15:29 +06: 0 / 0 hits

---

<div class="post-metadata">

**Author:** ![Salim\_Adnan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/salim_adnan/32/76864_2.png) [@Salim\_Adnan](https://discuss.elastic.co/u/Salim_Adnan)\
**Post date:** [September 9, 2021, 5:37am UTC](https://discuss.elastic.co/t/elastalert-send-me-0-hit-query-doesnt-work-please-help/283732/2 "2021-09-09T05:37:10Z")

</div>

any one please help me

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 9, 2021, 5:47am UTC](https://discuss.elastic.co/t/elastalert-send-me-0-hit-query-doesnt-work-please-help/283732/3 "2021-09-09T05:47:58Z")

</div>

Hi @Salim_Adnan

This community forum is to help with questions and issues with the official distributions of elasticsearch and / or Elastic Cloud hosted service.

Elastalert is not part of the default Elasticsearch distribution it is 3rd party plugin so perhaps it would be better to contact that project with your questions.

In addition it Also looks like perhaps you're using AWS managed elasticsearch  
which is also not part of the official elasticsearch distribution So perhaps you should visit the AWS Opensearch forum.

Of course we think the best distribution is the official distribution from elastic and perhaps you could try the new Kibana alerting framework and see if those would meet your needs.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 7, 2021, 5:48am UTC](https://discuss.elastic.co/t/elastalert-send-me-0-hit-query-doesnt-work-please-help/283732/4 "2021-10-07T05:48:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
