Hi
I used rsyslog to send log to ELK, like this guide How To Centralize Logs with Rsyslog, Logstash, and Elasticsearch on Ubuntu 14.04 | Elastic
Then I used grok to pars log's messages in logstash.conf
Now I want to create Alert, but I can't used logstash-* index in "Log threshold" filter.
What should I do?