alerting
alerting copied to clipboard
Doc level monitor should query all docs in each shard ingested since previous execution even if >10k docs per shard
If cluster ingests more than 10k docs per shard per minute, monitor lags behind the ingestion rate and will not be generating findings eventually (lag increases as ingestion keeps increasing)
Doc level monitor should query all docs in each shard ingested since previous execution even if >10k docs per shard