Watcher input index wildcard

alerting

(piyush) #1

Hi Team,
I am trying to put an alert on ERROR patterns. There are 4 development environments and i have to write 4 alerts for the same pattern search. Can we write an alert on multiple indexes?
If yes, how to put index name in watcher:

Alert input, (it's not working):
"indices": [
"<env-*-json-log-{now/d}>"
],

---***
<\env--json-log-{now/d}>
---
**

Indices are:
env-dev-json-log-2017.05.05
env-test-json-log-2017.05.05
env-qat-json-log-2017.05.05
env-uat-json-log-2017.05.05

Thanks & Regards,


(Alexander Reelsen) #2

Hey,

this query will most likely not work in Elasticsearch either, so this is not directly a watcher issue. What you could do, is to write your watch and specify the environment as part of the watch metadata, so that your four watches stay the same otherwise.

Alternatively you could also execute all four queries in one watch using a chained input.

Hope this helps!

--Alex


(system) #3

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.