Skip to content

Alert for Future Logs #1398

Closed Locked Answered by jertel
albertoCrego asked this question in Q&A
Mar 22, 2024 · 1 comments · 8 replies
Discussion options

You must be logged in to vote

Understood. I circled back to the first option and found that my initial run did search 7 days into the future. So I don't know why you're seeing a 24h cap on the query_delay. I used the following to test:

query_delay:
  days: -7
buffer_time:
  hours: 1

This resulted in a large number of queries, starting with this timerange

2024-03-25 08:17:05,342     INFO           elastalert Queried rule any_test39 from 2024-03-25 09:14 EDT to 2024-03-25 10:14 EDT: 0 / 0 hits

and ending with this

2024-03-25 08:17:06,018     INFO           elastalert Queried rule any_test39 from 2024-04-01 08:14 EDT to 2024-04-01 08:17 EDT: 0 / 0 hits

I did have to give it a --start 2024-03-25T12:14:00.000Z to force …

Replies: 1 comment 8 replies

Comment options

You must be logged in to vote
8 replies
@albertoCrego
Comment options

@jertel
Comment options

@albertoCrego
Comment options

@jertel
Comment options

Answer selected by jertel
@albertoCrego
Comment options

@jertel
Comment options

@albertoCrego
Comment options

@jertel
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants