Watcher: Action for each found document

I would like to perform actions per each document. For example, for each sudo command that is being executed, send a Slack notification.

I can't find any documentation for doing such watch.

See https://www.elastic.co/guide/en/elasticsearch/reference/7.4/action-foreach.html

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.