Skip to content

Flatline - 0 hits 0 matches - No Alert received #1434

Locked Answered by jertel
CaGix22 asked this question in Q&A
Discussion options

You must be logged in to vote

ElastAlert 2 is intended to be run continously. It is not designed to "wake up" every once in a while, run a query, and go back to sleep.

Limit execution is intended to be used for enabling ElastAlert 2 during smaller portions of the day. That's why the range of time is required in the cron format. Your cron format of 25 2-22/4 appears to be saying "execute at 25 minutes past every 4th hour between the hours of 02 and 22. That's not using ElastAlert 2 how it was intended since it's expecting to run at specific points in time within a range. A valid cron format for ElastAlert 2 would be * 2-22 * * 1-5 which means to enable rule checking from the entire time starting at 02:00 through 22:59 …

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@CaGix22
Comment options

@CaGix22
Comment options

Answer selected by CaGix22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants