clarify how to create combo queries with a tag
Signed-off-by: alicejw <alicejw@amazon.com>
This commit is contained in:
parent
7f866181d4
commit
95d03c0aa5
|
@ -11,7 +11,7 @@ redirect_from:
|
|||
OpenSearch Dashboards
|
||||
{: .label .label-yellow :}
|
||||
|
||||
OpenSearch Dashboards provides the Alerting plugin that allows you to monitor your data and create notifications that trigger when conditions occur in one or more indexes.
|
||||
OpenSearch Dashboards provides the Alerting plugin that allows you to monitor your data and create alert notifications that trigger when conditions occur in one or more indexes.
|
||||
|
||||
You create a monitor with trigger conditions that generate various alert notifications through the message channel you select as a destination. Notifications can be sent to email, Slack, or Amazon Chime.
|
||||
|
||||
|
|
|
@ -225,10 +225,10 @@ Document-level monitors provide the added option to use tags that represent mult
|
|||
To create a multiple query combination trigger:
|
||||
|
||||
1. Create a per document monitor with more than one query.
|
||||
2. Set the first query with field, operator and value. For example, set the query to search for the `region` field with either operator: "is" or "is not", and set the value "us-west-2".)
|
||||
3. Create a tag and give it a name.
|
||||
3. Set an additional query and add the same tag to it.
|
||||
4. Create the trigger condition and specify the tag name. This creates a combination trigger that checks two queries that both contain the same tag. The monitor checks both queries by a logical OR operation if either query's conditions are met, then it will generate the alert notification.
|
||||
2. Create the first query with field, operator and value. For example, set the query to search for the `region` field with either operator: "is" or "is not", and set the value "us-west-2".)
|
||||
3. Select **Add Tag** and give it a name.
|
||||
3. Create the second query add the same tag to it.
|
||||
4. Now you can create the trigger condition and specify the tag name. This creates a combination trigger that checks two queries that both contain the same tag. The monitor checks both queries by a logical OR operation if either query's conditions are met, then it will generate the alert notification.
|
||||
|
||||
### Extraction query
|
||||
|
||||
|
|
Loading…
Reference in New Issue