Welcome toVigges Developer Community-Open, Learning,Share
Welcome To Ask or Share your Answers For Others

Categories

0 votes
1.2k views
in Technique[技术] by (71.8m points)

elasticsearch - How to use wildcard in elastalert rules

I need help in ELASTALERT

I have a log message like this :

log.info("Server is started at "+LocalDateTime.now());

and I need to write a query in rule for it: I am writing as

- query:
      query_string:
        query: "message: *Server is*"

It seems like its not working. Can anyone tell me how to do it?


与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…
Welcome To Ask or Share your Answers For Others

1 Answer

0 votes
by (71.8m points)
等待大神答复

与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…
Welcome to Vigges Developer Community for programmer and developer-Open, Learning and Share
...