Skip to content
This repository has been archived by the owner on Apr 16, 2021. It is now read-only.

Elastalert Fields

weslambert edited this page Oct 24, 2017 · 3 revisions

Introduction

The following lists field names as they are formatted in Elasticsearch. Elastalert provides its own template to use for mapping into Elastalert, so we do not current utilize a config file to parse data from Elastalert.

index:*:elastalert_status

alert_info.type
alert_sent
alert_time
endtime
hist
matches
match_body.@timestamp
match_body.num_hits
match_body.num_matches
rule_name
starttime
time_taken

Clone this wiki locally