-
Hi there. This could be just me not understanding how flatline alerts are being triggered. I have a rule that looks for Suricata logs and what I'm wanting to do is send a Slack notification if there's 0 alerts in 5 minutes. Here's my rule:
Here's the elastalert output:
But I get a Slack notification every minute: What am I doing wrong here? Thanks! |
Beta Was this translation helpful? Give feedback.
Answered by
jertel
Apr 25, 2024
Replies: 1 comment 4 replies
-
Is the concern that you are receiving Slack alerts every 1 minute instead of every 5 minutes? |
Beta Was this translation helpful? Give feedback.
4 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Needs to be wrapped in quotes:
Or just get rid of the line altogether since it's the default. I wasn't sure why you were trying to override it in the first place, since your Kibana screenshot shows that the timestamp field starts with
@
.