I’m currently trying to get alerted on a field that is added by a pipeline stage such as this:
rule "extract error level" when true then let fields = regex(".* (ERROR|INFO|WARN|DEBUG) .*", to_string($message.message),["severity"]); set_fields(fields); end
As you can see the rule adds a field “severity”. Looking at the specific stream the pipeline is connected to the field is there and contains the right value. However, when I set up an alert condition (a simple field value condition for “serverity:ERROR”) I never get notified. Seems the alert condition doesn’t see the severity field added by the pipeline. Is this the expected behavior? Could someone explain please? Thanks!