Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Alerting] Event Correlation Rules for o11y #197148

Open
Erikg346 opened this issue Oct 21, 2024 · 2 comments
Open

[Alerting] Event Correlation Rules for o11y #197148

Erikg346 opened this issue Oct 21, 2024 · 2 comments
Labels
Team:obs-ux-management Observability Management User Experience Team

Comments

@Erikg346
Copy link

Describe the feature:

Add Event Correlation Rules to Observability or make it available to all.

Describe a specific use case for the feature:
Observability needs a way to also correlate events across data sources. It's not just for Security:
For example,
Set up a condition for log.level: error in the logs-* index.
Set up another condition for system.filesystem.used.pct >= 80% in the metrics-* index.

@botelastic botelastic bot added the needs-team Issues missing a team label label Oct 21, 2024
@mbondyra mbondyra added the Team:ResponseOps Label for the ResponseOps team (formerly the Cases and Alerting teams) label Oct 28, 2024
@elasticmachine
Copy link
Contributor

Pinging @elastic/response-ops (Team:ResponseOps)

@botelastic botelastic bot removed the needs-team Issues missing a team label label Oct 28, 2024
@cnasikas
Copy link
Member

cc @elastic/obs-ux-management-team @jasonrhodes

@cnasikas cnasikas added Team:obs-ux-management Observability Management User Experience Team and removed Team:ResponseOps Label for the ResponseOps team (formerly the Cases and Alerting teams) labels Oct 30, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Team:obs-ux-management Observability Management User Experience Team
Projects
None yet
Development

No branches or pull requests

4 participants