Skip to content

Alerting strategy question #1413

Locked Answered by jertel
smashley999 asked this question in Q&A
Apr 2, 2024 · 2 comments · 2 replies
Discussion options

You must be logged in to vote

I think I see what you're trying to do. You want a single instance of ElastAlert 2 to monitor N number of customer_N_alerts index for new records, and trigger outbound notifications using ElastAlert 2's numerous alerters. Is that correct?

If that's the intention then yes it would handle this but it would seem that you'd only be making use of half of ElastAlert 2's capabilities. If you look at the project you could say it's half detection and half alerting. The detection capabilities would be mostly unused since it would be up to the customers to ensure they have their own methodology for detecting an issue and creating a record in their alert index.

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
2 replies
@smashley999
Comment options

@jertel
Comment options

Answer selected by smashley999
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants