Skip to content
Discussion options

You must be logged in to vote

You should be able to remove the Elastalert indices and restart the service to recreate them,

sudo so-elasticsearch-query _cat/shards | grep elastalert 
sudo so-elasticsearch-query $INDEX_NAME -XDELETE
sudo so-elastalert-restart

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@byronsims
Comment options

Answer selected by byronsims
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants