How to get elastalert triger when the field sum for all documents matching the request exceeds some value

Can elastalert be called when the field sum for all documents matching the query exceeds a certain value? Say each document has a value. Can elastalert be triggered when the sum of the “price” values ​​for the last day exceeds 200, for example?

Document example:

{
  type: "transaction",
  price: 20.32
}

Example rule in English:

The sum of all documents where type = 'transaction' over the past hour exceeds 200

+3
source share
1 answer

This is not supported by ElastAlert.

, , pull request, .

ElastAlert, , , . .

0

Source: https://habr.com/ru/post/1655716/


All Articles