Skip to content
Discussion options

You must be logged in to vote

Hi,you can add the email alerting to the generic.template on path /opt/so/rules/elastalert/playbook/.
But I guess you have to deactivate and activate the rules again to get them parsed again.
Another option would be to create a single elastalert config which triggers when an alert gets written to the es-index.

Replies: 1 comment 5 replies

Comment options

You must be logged in to vote
5 replies
@rockbesst
Comment options

@keis3cker
Comment options

@rockbesst
Comment options

@keis3cker
Comment options

@rockbesst
Comment options

Answer selected by rockbesst
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants