Elastalert: Run time was missed #10164
Replies: 1 comment
-
Well, as a kind of thoughts: we use heavy-nodes and /nsm partition in some of them is not fast enough. It looks like if one heavy-node didn't respond on elastalert query, whole rule become delayed. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Hey!
SO 2.3.220, distributed setup.
I faced with such problem: sometime elastalert rules run with delay. Delay can be different: from minutes to even hours.
How I found it: some of alerts appeared in SOC interface much later than events were ingested. IE event happened in 15.00, alert in SOC created in 16.30.
I didn't find something strange in logs, except elastalert logs with this:
What can cause this problem?
Beta Was this translation helpful? Give feedback.
All reactions