I am currently working on Kibana Alerting and what I wanted to perform is basically "Log threshold".
Please see attached for the details of the alert rule.
I wanted to match phrase of the word "warnings" on the field "message". However, when i saved it, the alarm is not "Active" status went from active to OK. When i removed the AND message MATCHES PHRASE "warnings" that's when the alert is going to be in Active Status and is firing Anyone knows what is wrong with my ruling?
Thanks in advance!