Skip to content

[Alerting] Add "Group By" support to ES Query alert type #89481

@ymao1

Description

@ymao1

This PR introduced a basic ES query alert type that allows users to specify a query and a threshold condition for the number of matches against that query. We would like to enhance this alert type by adding the ability to group by a field within the index and then threshold against the hits within each group.

Metadata

Metadata

Assignees

Labels

Feature:Alerting/RuleTypesIssues related to specific Alerting Rules TypesTeam:ResponseOpsPlatform ResponseOps team (formerly the Cases and Alerting teams) t//enhancementNew value added to drive a business resultestimate:mediumMedium Estimated Level of Effort

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions