Hello,
we are trying to generate a Log Threshold rule that requires checking a boolean field to detect if the alert must be raised or not, but UI interface does not allow to use this kind of fields.
We have checked the documentation and it does not mention anything related to this.
Here is a screen capture of the rule form:
And here is the field in the index:
As a workaround we are planning to remap that field to a text/keyword field type, but we want to know if there is another workaround or if it is a bug or a planned feature.
Thanks in advance.