I want to monitor the amount of events for a period with a treshold.
How can I set this in an alert rule?
I want to monitor the amount of events for a period with a treshold.
How can I set this in an alert rule?
Hello @Lev2
Welcome to the Community!!
If you could share the usecase in more detail than as per that can provide proper suggestion.
Still for basic can use => "Index threshold rule" & set the conditions/actions as per your requirement.
Example :
Rule : With KQL filter
response : 503
Thanks!!
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.