One alert for all unique event.action from all events in last 30mins

Version: ELK 7.13
Need to generate a single alert for all events with unique event.action feild values in last 30minute.

Can someone please let me know which rule type I can use here? Also please share if you have any sample.

I have tried following without success.

  1. Threshold rule Detection - But here I have to give a threshold number and unique value number, in my actual requirement there is no such number limit.

  2. Custom Rule: There is no option to aggregate/group by one field and send alert based on this.

Thanks in advance.

What if you do this?

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.