When creating an alert in kibana with “define using visual graph” the field “OVER ALL DOCUMENTS” should support aggregation but it currently does not. It always shows “over all documents” regardless of what settings are configured in other fields.
This is a very basic and highly used feature in other alerting tools (x-pack or elastalert) which allows use cases such as grouping on beat.name so one alert can cover multiple hosts. Right now separating alerts by host can only be implemented with “define using extraction query” (removes simplicity) or by implementing one alert for each host (creates a mess).
Using elasticsearch 7.1.1 with kibana 7.1.1 on linux
kibana-alerting 184.108.40.206 and kibana-alerting-elasticsearch 220.127.116.11 built from github then installed into elasticsearch as a plugin.
Also reported on github: https://github.com/opendistro-for-elasticsearch/alerting-kibana-plugin/issues/68