Field Content Alert

(Si Ya Ni) #1


Is there a way I can set the alert condition to match a string exactly, for example, “Unknown Protected Resource”? The documentation said it will trigger the alert as long as it matches one of the words.

Thank you,
Si Ya Ni

Alerting question
(Jochen) #2

The value of the field content alert condition is basically a quoted Lucene/Elasticsearch query.
So if you create a field content alert condition for the field “foobar” with the value “Lorem ipsum dolor sit amet”, it will generate the following Elasticsearch query:

foobar:"Lorem ipsum dolor sit amet"

Depending on the configuration for the field “foobar” (e. g. analyzed or not analyzed), this will yield different results.

(Si Ya Ni) #3

Thank you for your help.

(system) closed #4

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.