Unique Count for Alerts?
Posted: Mon Oct 14, 2019 3:20 am
Hi there,
I was wondering if there's any way I can make an alert that uses unique count instead of just a threshold?
For example: I wan't to make a simple failed login alert, but I'm finding it nearly impossible to get it to a usefull state because the alert-tool is looking on all events as a whole, and not just the logoutput per host.
In other ELK-based solutions it's a feature so I was wondering if I was missing it or something - as it seems like a pretty important tool to have when making alerts.
This problem spills over into panels, where it would be nice to have as well.
Thanks in advance
,
I was wondering if there's any way I can make an alert that uses unique count instead of just a threshold?
For example: I wan't to make a simple failed login alert, but I'm finding it nearly impossible to get it to a usefull state because the alert-tool is looking on all events as a whole, and not just the logoutput per host.
In other ELK-based solutions it's a feature so I was wondering if I was missing it or something - as it seems like a pretty important tool to have when making alerts.
This problem spills over into panels, where it would be nice to have as well.
Thanks in advance