How to merge messages form hits? #1570
-
Hi, I use this config, it runs every 5 minutes, and when hits > 1, it will send an alert, but it's |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 3 replies
-
First, you didn't provide the full rule config so I'm going blind here. Is it a frequency rule? Second, you state that you want an alert only when What do you mean by "merge data"? If your rule finds 10,000 matches, are you wanting to blast 10,000 lines of event data in your alert message? Or are you wanting to sum or average a specific numeric field? |
Beta Was this translation helpful? Give feedback.
This is answered in the FAQ.