You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Is your feature request related to a problem? Please describe.
Problem statement: monitor for a condition with less than operator, supporting 0.
Describe the solution you'd like
I'm trying to implement a rule for monitoring when a rule hasn't has any alerts in X time period. Threshold rule only supports greater than and trying in ESQL counting also doesn't not count unless a value is present.
Describe alternatives you've considered
Here's an example in ESQL counting the number of building block alerts:
from .alerts-security.alerts
| where kibana.alert.building_block_type == "default"
| stats alert_count = count(*) by kibana.alert.rule.name
| where alert_count == 0
I want to know if a building block rule has 0 alerts in the last 1 week.
The text was updated successfully, but these errors were encountered:
Is your feature request related to a problem? Please describe.
Problem statement: monitor for a condition with less than operator, supporting 0.
Describe the solution you'd like
I'm trying to implement a rule for monitoring when a rule hasn't has any alerts in X time period. Threshold rule only supports greater than and trying in ESQL counting also doesn't not count unless a value is present.
Describe alternatives you've considered
Here's an example in ESQL counting the number of building block alerts:
I want to know if a building block rule has 0 alerts in the last 1 week.
The text was updated successfully, but these errors were encountered: