Monitor Alerting Query

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser):
v 2.7.0

Describe the issue:
One of our team is looking to have an alert configured for failure in documents in response for one of the protocol…

The fields we would like to query are:

  1. role
  2. message

Need to search for this: ‘GET /v1/execute/’
System: xyz_protocol_http_get
role: HTTP GET

Can someone provide how this can be done in opensearch using any query?
Manual configuration with filters doesn’t populate any values.


Relevant Logs or Screenshots:

I tried below configuration which doesn’t show any preview, doubt it should or shouldn’t…