However, I would like to modify this rule so that it execute the rule only when a new packet with the field event.wlan-src arrives, rather than continuously counting the packets. Is it technically possible to set up such a rule in Kibana without requiring a paid license?
But I'm not sure that's what I want, as the description of a ‘new Term rule’ is that we want to detect new packets.
Here, I want the rule to run each time a new packet meets the conditions. Basically, if I don't receive a matching packet for 10 hours, I don't want the rule to run.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.