In my example data as you see there are the “device” field and “total_count” fields. I have 2 devices, a computer, and a phone I want to send an alert when these devices have over 10 “total_count”. I can alert when the total_count field is above 10 but I also want to group-by the alert by the “device” field. But when I tried that I couldn’t be able to see my device field in the group-by section.
Mappings for my data:
“device” field is “text”
“total_count” field is “long”
My 2nd question is when I created an alert it also sends alerts while the alert’s status is alerting. Since my alert works every minute this means back-to-back same alerts every minute. This is an issue for me because I don’t want to get the same alert every minute. Can I prevent this?
As far as I know, the terms aggregation (which is what’s being applied on the group by fields here), cannot be done on a text field directly. You’ll want to provide a keyword subfield for the text field and aggregate on that.
Here is what an example mapping would look like for device: