Hi it seems alerts is just triggering one time and after that alerts is not triggering for any new events.
Mean , i acknowledge one alerts , then i created same event again for the same alerts , but alerts didn’t trigger.
1.)
"_id" : "BmO3j2kBBSkdQvmwHoOt",
"_version" : 6,
"monitor" : {
"type" : "monitor",
"name" : "User Created",
"enabled" : true,
"enabled_time" : 1552894335947,
"schedule" : {
"period" : {
"interval" : 1,
"unit" : "MINUTES"
}
},
"inputs" : [
{
"search" : {
"indices" : [
"winlogbeat-2019.03.19"
],
"query" : {
"size" : 100,
"query" : {
"match" : {
"event_id" : {
"query" : "4720",
"operator" : "OR",
"prefix_length" : 0,
"max_expansions" : 50,
"fuzzy_transpositions" : true,
"lenient" : false,
"zero_terms_query" : "NONE",
"auto_generate_synonyms_phrase_query" : true,
"boost" : 1.0
}
}
}
}
}
}
],
"triggers" : [
{
"id" : "C2O3j2kBBSkdQvmwjINP",
"name" : "User Created",
"severity" : "2",
"condition" : {
"script" : {
"source" : "ctx.results[0].hits.total > 0",
"lang" : "painless"
}
},
"actions" : [ ]
}
],
"last_update_time" : 1552979590597
}
}
2.)
{
"took" : 18,
"timed_out" : false,
"_shards" : {
"total" : 5,
"successful" : 5,
"skipped" : 0,
"failed" : 0
},
"hits" : {
"total" : 1,
"max_score" : 1.0,
"hits" : [
{
"_index" : ".opendistro-alerting-alerts",
"_type" : "_doc",
"_id" : "EWO4j2kBBSkdQvmwBoNM",
"_score" : 1.0,
"_routing" : "BmO3j2kBBSkdQvmwHoOt",
"_source" : {
"monitor_id" : "BmO3j2kBBSkdQvmwHoOt",
"monitor_version" : 2,
"monitor_name" : "User Created",
"trigger_id" : "C2O3j2kBBSkdQvmwjINP",
"trigger_name" : "User Created",
"state" : "ACKNOWLEDGED",
"error_message" : null,
"alert_history" : [ ],
"severity" : "2",
"start_time" : 1552894395778,
"last_notification_time" : 1552894456006,
"end_time" : null,
"acknowledged_time" : 1552894473452
}
}
]
}
}
3.)
id name active rejected completed
4jPUFB8aQuuTWcgpHyhOxw opendistro_monitor_runner 0 0 66
4.){
"_nodes" : {
"total" : 1,
"successful" : 1,
"failed" : 0
},
"cluster_name" : "elasticsearch",
"opendistro.scheduled_jobs.enabled" : true,
"scheduled_job_index_exists" : true,
"scheduled_job_index_status" : "green",
"nodes_on_schedule" : 1,
"nodes_not_on_schedule" : 0,
"nodes" : {
"4jPUFB8aQuuTWcgpHyhOxw" : {
"name" : "4jPUFB8",
"schedule_status" : "green",
"roles" : [
"MASTER",
"DATA",
"INGEST"
],
"job_scheduling_metrics" : {
"last_full_sweep_time_millis" : 189817,
"full_sweep_on_time" : true
},
"jobs_info" : {
"BmO3j2kBBSkdQvmwHoOt" : {
"last_execution_time" : 1552980675947,
"running_on_time" : true
},
"BS_OlGkB8nQEAav636lN" : {
"last_execution_time" : 1552980679375,
"running_on_time" : true
}
}
}
}
}