# Relaert is not working in frequency rule type

**URL:** <https://discuss.elastic.co/t/relaert-is-not-working-in-frequency-rule-type/161202>\
**Category:** Elasticsearch\
**Created:** [December 17, 2018, 8:16pm UTC](https://discuss.elastic.co/t/relaert-is-not-working-in-frequency-rule-type/161202 "2018-12-17T20:16:42Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sudhakar\_katakara](https://avatars.discourse-cdn.com/v4/letter/s/977dab/32.png) [@sudhakar\_katakara](https://discuss.elastic.co/u/sudhakar_katakara)\
**Post date:** [December 17, 2018, 8:16pm UTC](https://discuss.elastic.co/t/relaert-is-not-working-in-frequency-rule-type/161202/1 "2018-12-17T20:16:42Z")

</div>

I am using below parameters in frequency rule type but realert is not working on specified time duration. I have mentioned relaert with hours : 1 and queary\_key : "Hostname" ie since realert is 1 hour I assume it should aggregate records based on hostname field for the hour (assume from 9:00 to 10:00) and as num\_events : 1 hence it should raise only one alarm per hostname eventhough hostname have more events in that hr. it is working as expected. But if the event comes after one hr ie at 10:25, the alarm is not getting generated. currently I haven't configured any alert notification. I can see them are supressed in console.

rule file has:  
es\_host: localhost  
es\_port: 9200  
rules\_folder : "D:\elastalert-master\example\_rules"  
buffer\_time :  
hours : 4

timeframe:  
days : 4

writeback\_index : test\_elastalert1  
name: test5 rule  
type: frequency  
timestamp\_field: "time"  
index: test\_elastalert1  
num\_events: 1  
aggregation:  
#minutes: 10  
days : 1  
aggregation\_key : "Hostname"  
query\_key : "Hostname"

realert :  
hours : 1  
filter:

- query:  
match :  
"event\_message" : "Ping"

alert: "email"  
alert\_subject: "Issue is occurred "  
alert\_info: "event from "

* * *

elastalert-test-rule

D:\elastalert-master\example\_rules\>elastalert-test-rule test5.yaml  
Successfully loaded test5 rule

Got 4 hits from the last 1 day

Available terms in first hit:  
event\_message  
event\_sev  
Hostname  
event\_source  
time

INFO:elastalert:Note: In debug mode, alerts will be logged to console but NOT actually sent.  
To send them but remain verbose, use --verbose instead.  
INFO:elastalert:Queried rule test5 rule from 2018-12-16 14:13 Central Standard Time to 2018-12-16 18:13 Central Standard Time: 0 / 0 hits  
INFO:elastalert:Queried rule test5 rule from 2018-12-16 18:13 Central Standard Time to 2018-12-16 22:13 Central Standard Time: 0 / 0 hits  
INFO:elastalert:Queried rule test5 rule from 2018-12-16 22:13 Central Standard Time to 2018-12-17 02:13 Central Standard Time: 0 / 0 hits  
INFO:elastalert:Queried rule test5 rule from 2018-12-17 02:13 Central Standard Time to 2018-12-17 06:13 Central Standard Time: 0 / 0 hits  
INFO:elastalert:Queried rule test5 rule from 2018-12-17 06:13 Central Standard Time to 2018-12-17 10:13 Central Standard Time: 4 / 4 hits  
INFO:elastalert:Queried rule test5 rule from 2018-12-17 10:13 Central Standard Time to 2018-12-17 14:13 Central Standard Time: 0 / 0 hits  
INFO:elastalert:New aggregation for test5 rule, aggregation\_key: lv00001. next alert at 2018-12-18 20:13:44.943000+00:00.  
INFO:elastalert:Ignoring match for silenced rule test5 rule.lv00001  
INFO:elastalert:New aggregation for test5 rule, aggregation\_key: lv00002. next alert at 2018-12-18 20:13:44.950000+00:00.  
INFO:elastalert:Ignoring match for silenced rule test5 rule.lv00002

Would have written the following documents to writeback index (default is elastalert\_status):

silence - {'rule\_name': u'test5 rule.lv00001', '@timestamp': datetime.datetime(2018, 12, 17, 20, 13, 44, 938000, tzinfo=tzutc()), 'exponent': 0, 'until': d  
atetime.datetime(2018, 12, 17, 21, 13, 44, 938000, tzinfo=tzutc())}

elastalert - {'alert\_info': {}, 'alert\_sent': False, 'match\_body': {'\_type': u'record', u'event\_source': u'BPPM', '\_index': u'test\_elastalert1', 'num\_hits'  
: 4, u'event\_sev': u'Critical', u'Hostname': u'lv00001', u'event\_message': u'ping response is failed ', u'time': '2018-12-17T13:01:04.572Z', 'num\_matches':  
4, '\_id': u'9'}, 'rule\_name': 'test5 rule', 'match\_time': '2018-12-17T13:01:04.572Z', 'alert\_time': datetime.datetime(2018, 12, 18, 20, 13, 44, 943000, tz  
info=tzutc()), 'aggregation\_key': u'lv00001', 'alert\_exception': None}

silence - {'rule\_name': u'test5 rule.lv00002', '@timestamp': datetime.datetime(2018, 12, 17, 20, 13, 44, 949000, tzinfo=tzutc()), 'exponent': 0, 'until': d  
atetime.datetime(2018, 12, 17, 21, 13, 44, 949000, tzinfo=tzutc())}

elastalert - {'alert\_info': {}, 'alert\_sent': False, 'match\_body': {'\_type': u'record', u'event\_source': u'DYNA', '\_index': u'test\_elastalert1', 'num\_hits'  
: 4, u'event\_sev': u'Critical', u'Hostname': u'lv00002', u'event\_message': u'ping response is failed ', u'time': '2018-12-17T13:05:27.706Z', 'num\_matches':  
4, '\_id': u'13'}, 'rule\_name': 'test5 rule', 'match\_time': '2018-12-17T13:05:27.706Z', 'alert\_time': datetime.datetime(2018, 12, 18, 20, 13, 44, 950000, t  
zinfo=tzutc()), 'aggregation\_key': u'lv00002', 'alert\_exception': None}

elastalert\_status - {'hits': 4, 'matches': 4, '@timestamp': datetime.datetime(2018, 12, 17, 20, 13, 44, 952000, tzinfo=tzutc()), 'rule\_name': 'test5 rule',  
'starttime': datetime.datetime(2018, 12, 16, 20, 13, 44, 869000, tzinfo=tzutc()), 'endtime': datetime.datetime(2018, 12, 17, 20, 13, 44, 869000, tzinfo=tz  
utc()), 'time\_taken': 0.06799983978271484}

D:\elastalert-master\example\_rules\>

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 17, 2018, 8:18pm UTC](https://discuss.elastic.co/t/relaert-is-not-working-in-frequency-rule-type/161202/2 "2018-12-17T20:18:28Z")

</div>

What is relaert?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 18, 2018, 7:39am UTC](https://discuss.elastic.co/t/relaert-is-not-working-in-frequency-rule-type/161202/3 "2018-12-18T07:39:28Z")

</div>

As this seems related to Elastalert, I would recommend you reach out to their community as you may get an answer faster that way.

---

<div class="post-metadata">

**Author:** ![sudhakar\_katakara](https://avatars.discourse-cdn.com/v4/letter/s/977dab/32.png) [@sudhakar\_katakara](https://discuss.elastic.co/u/sudhakar_katakara)\
**Post date:** [December 18, 2018, 4:52pm UTC](https://discuss.elastic.co/t/relaert-is-not-working-in-frequency-rule-type/161202/4 "2018-12-18T16:52:12Z")

</div>

Hi Christian, Thanks for your replay. can you please let me know whats the elastalert community site?  
is it [https://github.com/Yelp/elastaler](https://github.com/Yelp/elastaler) ?  
Thanks,  
Sudhakar

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 18, 2018, 6:24pm UTC](https://discuss.elastic.co/t/relaert-is-not-working-in-frequency-rule-type/161202/5 "2018-12-18T18:24:27Z")

</div>

I have no idea as I have never used Elastalert.

---

<div class="post-metadata">

**Author:** ![sudhakar\_katakara](https://avatars.discourse-cdn.com/v4/letter/s/977dab/32.png) [@sudhakar\_katakara](https://discuss.elastic.co/u/sudhakar_katakara)\
**Post date:** [December 18, 2018, 6:25pm UTC](https://discuss.elastic.co/t/relaert-is-not-working-in-frequency-rule-type/161202/6 "2018-12-18T18:25:52Z")

</div>

ok Thanks . I have posted my question in the above mentioned community.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 15, 2019, 6:25pm UTC](https://discuss.elastic.co/t/relaert-is-not-working-in-frequency-rule-type/161202/7 "2019-01-15T18:25:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
