How to write alert rule in Elastalert

I have configured metricbeat-Elasticsearch-kibana to monitor docker containers metric. and Elastalert to get email alert.
I am getting CPU, memory, Network usage perfectly.
and getting docker container status as field: "docker.container.status"= Up 5 min"
need to get alert in Elastalert when container will get stopped or paused.
It will be great if anyone can help me to write elastalert rule to get alert.

1 Like

This forum is about software developed by Elastic. Elastalert is a third-party, so you might not get much help here.

I suggest that you try another forum such as Stackoverflow.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.