官术网_书友最值得收藏!

How it works...

Alert rules automatically run log searches at regular intervals that you define in the rule. If the log search returns results that match the defined criteria, then an alert record is created and an action can be performed, based on what you define in the alert rule.

The following properties are required in an alert rule:

  • Search query: The query upon which an alert rule is based will run every time the alert rule executes.
  • Time window: The time range of current time for which records are returned by the search query. This time window can range between 5 minutes and 24 hours. For instance, if you set the range to the default 15 minutes and the query is run at 12:00 PM, the search query will return only records created between 11:45 PM and 12:00 PM.
  • Alert frequency: This determines how often the search query is run. The alert rule frequency can be between 5 minutes and 24 hours. Importantly, the alert rule frequency should be less than or equal to the time window, in order for the query to accurately return relevant records.
  • Threshold: This depends on the type of alert rule created, and when defined, determines when search query results will generate alerts. See the following Alert rule types section.
  • Suppress alerts: This feature helps to reduce noise. When enabled, and after the alert rule creates a new alert, it disables actions for the rule for a length of time that you define in minutes or hours.
主站蜘蛛池模板: 黄山市| 安陆市| 东兰县| 呼伦贝尔市| 抚松县| 平顺县| 青龙| 皋兰县| 吉木乃县| 青浦区| 涿鹿县| 锡林郭勒盟| 大城县| 榕江县| 西平县| 永春县| 铁岭市| 巧家县| 通化县| 六盘水市| 高平市| 龙州县| 大宁县| 千阳县| 商水县| 清徐县| 长沙县| 景洪市| 广丰县| 朝阳区| 巴彦县| 长葛市| 宣化县| 伊川县| 洪雅县| 高陵县| 齐齐哈尔市| 民乐县| 北海市| 金沙县| 正定县|