Skip to content

Question about rule functioning #1415

Closed Locked Answered by jertel
ngms17 asked this question in Q&A
Discussion options

You must be logged in to vote

The query hits value in the last log line is misleading. It's only representing the most recent query, even though this rule run consisted of multiple queries (broken into time segments). The log line could show cumulative hits, but for whatever reason the author chose to show the most recent queries hits.

Regardless, the number of matches is the important metric in that log line. It's saying that neither of the two queries for this rule run found a match. It would depend on the rule type and rule parameters to determine what constitutes a match.

Terminology:

Hits are the number of records the query found.
Matches are the number of times the query records exceeded the threshold for the ru…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@ngms17
Comment options

Answer selected by jertel
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants