can I filter an alarm state OK value, we want to close an alert based on alarm status.
using "detail" and regex combination - filter does not work.
using "detailMap" requires string either a key or value which doesn't work since it's nested JSON
{
"version": "0",
"id": "xx",
"detail-type": "CloudWatch Alarm State Change",
"source": "aws.cloudwatch",
"account": "xx",
"time": "2023-07-24T07:20:41Z",
"region": "eu-west-2",
"resources": [
"arn:aws:cloudwatch:eu-west-2:xx:alarm:Module-xx-API-xx-4xx"
],
"detail": {
"alarmName": "xx-nonprod-Test-Alarm",
"state": {
"value": "ALARM",
"reason": "Threshold Crossed: 1 out of the last 1 datapoints [0.5 (24/07/23 07:15:00)] was greater than the threshold (0.1) (minimum 1 datapoint for OK -> ALARM transition).",
"timestamp": "2023-07-24T07:20:41.222+0000"
},
"previousState": {
"value": "INSUFFICIENT_DATA",
"reason": "Insufficient Data: 1 datapoint was unknown.",
"timestamp": "2023-07-24T07:07:41.220+0000"
},
"configuration": {
"metrics": [
{
"id": "xx-5dbe-8bd2-03eb-xx",
"metricStat": {
"metric": {
"namespace": "AWS/ApiGateway",
"name": "4xx",
"dimensions": {
"ApiId": "xx"
}
},
"period": 300,
"stat": "Average"
},
"returnData": true
}
],
"description": "Monitors the 4xx errors threshold"
}
}
}
PS: we are using CloudWatch event and not CloudWatch alarms Integration to avoid some duplication