We are attempting to make a Log Threshold alert, however it is sending alerts when it shouldn't be. The query we are trying to alert on is
labels.application: "theapp" and message: "*limit request headers fields size*". Inside the log threshold alert we have:
WHEN more than or equals 1 log entry WITH labels.application IS theapp AND message MATCHES PHRASE limit request headers fields size FOR THE LAST 10 minutes
Is there any documentation for the different types of alerts you can make? On https://www.elastic.co/guide/en/kibana/current/alert-types.html it only details the index threshold.