Skip to content

docker-compose elastalert not working on restart #680

Closed Locked Answered by jertel
vibarco asked this question in Q&A
Discussion options

You must be logged in to vote

I don't understand this statement:

and elastalert is not resuming until past hours, no activity in alert_status_status

ElastAlert 2 will not re-alert on something it's already alerted on. However, if you change the name of the rule, then it will re-alert on everything again, since it has no stored knowledge of already having executed searches and alerts for that new rule name.

Replies: 1 comment 10 replies

Comment options

You must be logged in to vote
10 replies
@vibarco
Comment options

@jertel
Comment options

@vibarco
Comment options

@jertel
Comment options

@vibarco
Comment options

Answer selected by jertel
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants