KQL Search Alert #91860
Labels
enhancement
New value added to drive a business result
estimate:medium
Medium Estimated Level of Effort
Feature:Alerting/RuleTypes
Issues related to specific Alerting Rules Types
Team:ResponseOps
Label for the ResponseOps team (formerly the Cases and Alerting teams)
As a followup to #61313, we also want to allow a KQL search alert in addition to ES DSL. This could be potentially part of the same search alert with a switch to allow entering KQL or ES DSL (or Lucene as well).
See comments #61313 for some initial discussion about KQL
The text was updated successfully, but these errors were encountered: