so-detection refresh_interval => 1s

Speeds up the refresh_interval so bulk indexing a single rule does not wait 30s.
This commit is contained in:
Corey Ogburn
2024-07-25 12:53:04 -06:00
parent f447b6b698
commit 20f915f649

View File

@@ -296,7 +296,7 @@ elasticsearch:
limit: 1500
number_of_replicas: 0
number_of_shards: 1
refresh_interval: 30s
refresh_interval: 1s
sort:
field: '@timestamp'
order: desc