Hi @spinscale, sorry for the late reply,
I get syslogs from many machines, I got to alert whenever a syslog message contains the string: "down", so in the range of one minute, could be many matches of the string "down",
but it seems that watcher only get me the first match it finds.
You are typically not interested in single down events, but rather in grouping those, for example ten down events from a single node do not matter, but the nodename is important.
You may want to take a look at aggregations to properly solve this.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.