Thanks... for the Log Threshold Rule when you set a "group by" field, like host.name, then the alert.id would equal the value of the host.name, like db.foo.com. For Log Threshold rules without a "group by" field, we set the alert.id to * (an asterisk), which represents "everything".
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.