0

I'm using a custom rule with a custom alerter that writes the alerts in a text file, and i'd like not to have the name of the rule written before alerts, given that only that specific rule will write in this file.

Is there any option to only write the rule type text or the alert text ?

Or something to create my own alert text type ? Ideally i'd like my alert texts to be only the ruletype_text

Daienkai
  • 1
  • 2

1 Answers1

0

Please refer to my question here it might help.

The answer in above question links to this Documentation of elastalert, there are some arguments which you can specify in your rule to filter the alert data.

OR try playing with the name of the rules files (alert.yaml or __.yaml)This is just a guess though.

Community
  • 1
  • 1
XOR-Manik
  • 493
  • 1
  • 4
  • 19