Skip to content
Discussion options

You must be logged in to vote

I found that if I moved all of the rules in the /opt/so/rules/elastalert/rules/custom/*.yml to someplace like /opt/so/rules/save/ and ran so-rule-update ; so-elastalert-restart. The elastalert process would parse the remaining rules and run sucessfully.

With this I should close this ticket and open a new one for getting the custom rules to work.

Replies: 2 comments 5 replies

Comment options

You must be logged in to vote
4 replies
@danielbidwell
Comment options

@dougburks
Comment options

@danielbidwell
Comment options

@reyesj2
Comment options

Comment options

You must be logged in to vote
1 reply
@danielbidwell
Comment options

Answer selected by danielbidwell
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
3 participants