Hi Everyone,
I have one requirement.
I have created one Error message Alert as below:
index=abc ns=xyz CASE(ERROR)|rex field=_raw "ERROR(?<Error_Message>.*)" |eval _time = strftime(_time,"%Y-%m-%d %H:%M:%S.%3N")| cluster showcount=t t=0.3|table app_name, Error_Message ,cluster_count,_time, environment, pod_name,ns |dedup Error_Message| rename app_name as APP_NAME, _time as Time, environment as Environment, pod_name as Pod_Name,cluster_count as Count
But from this I am duplicate alert.
Entire Data is coming same except count.
Can someone guide me what should I remove from query.
Hi @aditsss,
have you a duplicated alert because:
In the first case, the only way is to have a Search Head Cluster that manages the alert's execution.
In the second case, you can disable the alert after an occurrance for a defined time.
Ciao.
Giuseppe