All Alerts are mistakenly triggered

Hi guys,

I run into problems, when my Opensearch cluster (only 2 nodes…, v2.1.0) lost the connection due to problems with one node.

After the loss of connection, all configured alerts were triggered, because the system got no data from OpenSearch.

Is this behavior usual?

I configured in all my alerts that the system looks for special event id’s (count > XY). So I am surprised that this kind of behavior occurred.