i have an issue with alerting systeme ing raylog, even tho the messages are passing the rule, not all of them triggering alerts, some work some no, smae grok, same format, but not all of them working
stream : ssh bruteforce
rule : message must contain Disconnecting: Too many authentication failures for
alert condition : Alert is triggered when there are more than 0 messages in the last 3 minutes. Grace period: 1 minute. Not including any messages in alert notification.
i tried increasing time window to 3 and 5, same thing
Thanks in advance