Elastalertrule - exclude ip#

(Martin)

I need help to exclude an IP# in a rule.

This rule watches for firewall_rejects. I have started with this:

- regexp:
** ip_address: "^(?!*$"**

I do not need alertings or emails from the IP# in this rule, what is to do?


(Thiago Souza)

This forum is for official Elastic software. For Elastalert I suggest that you try some other discussion forum such as StackOverflow or maybe ask the authors directly.



