Skip to content

Question on frequency rule behavior - need some light on how run_every and timeframe params are used to determine a match #554

Closed Locked Answered by jertel
rpotnuru asked this question in Q&A
Discussion options

You must be logged in to vote

Hello. The subject of this discussion is misleading. It's stating that frequency rules do not respect the timeframe parameter. However, it appears more like you are unsure of how ElastAlert 2 is designed to function.

All rules are queried against Elasticsearch every 1 minute, or as specified in the run_every parameter. Upon each execution, the rule looks backward over the specified timeframe to determine if an alert should be triggered.

Replies: 2 comments 4 replies

Comment options

You must be logged in to vote
4 replies
@rbkumar88
Comment options

@jertel
Comment options

@rbkumar88
Comment options

@jertel
Comment options

Answer selected by jertel
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants