Skip to content
Discussion options

You must be logged in to vote

The reason you're only getting one match included in the alert is because of the timing configurations within your rule. You have realert set to silence alerts for a full minute after encountering a match. And then you have aggregation set for a 1 minute window as well. So you're defeating the purpose of the aggregation by using a matching realert setting. Try using a realert window that is shorter than the aggregation window:

realert:
  seconds: 1

aggregation:
  minutes: 1

With this configuration you'll get up to 60 matches per alert. Or, remove the realert altogether from both the config.yaml and your rule to get every match.

Replies: 2 comments 3 replies

Comment options

You must be logged in to vote
2 replies
@Treeefort
Comment options

@Treeefort
Comment options

Comment options

You must be logged in to vote
1 reply
@Treeefort
Comment options

Answer selected by Treeefort
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants