I've just figured out that kibana alerting, the
index threshold rule type does not support chaining rules (Suppose a situation that you want to calculate values from two separate queries and set a condition on the difference of those values)
Setting elasticsearch watcher might be reasonable but it needs subscription :D
I wonder if
elastalert package would help us in having alerts on desired query rules? Any idea is appreciated.
Subscribe to get latest updates