[beginner ] new_term rule
See original GitHub issueHello,
I’m new to elastalert, i’m getting logs from twitter, i try to get all the new values from “place.country_code” field, my rule conf contains:
type: new_term
index: twitter
fields:
- place.country_code
terms_window_size:
days: 90
use_terms_query: true
doc_type: logs
query_key: "place.country_code"
filter: []
but when i run my logstash and elastalert, i’m getting alerts from place.country_code values that i already get, it’s like it ignores the terms_window_size. (if I let the two run it works and alerts only on new values).
Issue Analytics
- State:
- Created 7 years ago
- Comments:5 (2 by maintainers)
Top Results From Across the Web
[Question] Setting NewTerm as default shell script handler
I was wondering if there was an easy way to automatically run all .sh scripts in NewTerm or a comparable terminal? Essentially, I...
Read more >A beginner's guide to kerning like a designer - Canva
As a general rule of thumb, you can get away with tighter kerning at larger sizes, but letters can look closer together at...
Read more >CITI Training: Revised Common Rule Flashcards - Quizlet
The Final Rule added the requirement that: Key information essential to decision making receive priority by appearing at the beginning of the consent...
Read more >Recursive Rule Formulas & Examples | Geometric, Arithmetic ...
This formula means "start at 100, and subtract 5 for each new term." If we want to calculate the 4th term of this...
Read more >As Supreme Court Starts New Term, Some Cases to Watch
Wade and rule that the Second Amendment protects citizens' right to carry a gun outside their home, a new slate of cases before...
Read more >
Top Related Medium Post
No results found
Top Related StackOverflow Question
No results found
Troubleshoot Live Code
Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free
Top Related Reddit Thread
No results found
Top Related Hackernoon Post
No results found
Top Related Tweet
No results found
Top Related Dev.to Post
No results found
Top Related Hashnode Post
No results found

Well, I think issues like this, after more than two years, could be closed. It’s necessary a cleanup.
I’ve been meaning to do another old issue purge…