官术网_书友最值得收藏!

There's more...

When the criteria defined in an alert rule is matched by the results of the search query, then an alert record is created. These records are stored as events in the Alert table in the OMS repository and are of type alert. Alert records created by alert rules in Log Analytics have a SourceSystem property value of OMS. This can be used to distinguish them from alert records from other sources, such as SCOM and the Alert Management solution.

You can use this query to find alert records in your workspace:

Alert
| summarize count () by SourceSystem

This query aggregates the content of the Alert table and returns the count of alert records by the SourceSystem property:

Figure 3.6

You can view the properties of an alert record generated by a Log Analytics alert rule by specifying the OMS SourceSystem value in your search query:

Alert
| where SourceSystem == "OMS"

In the resulting field, click the [+] show more button to expand the result view for one of the alert records. This will display all of the alert record properties and corresponding property values:

Figure 3.7
主站蜘蛛池模板: 赤峰市| 宝应县| 武陟县| 辰溪县| 城步| 霸州市| 西峡县| 渝中区| 元朗区| 枣强县| 宁晋县| 伊春市| 邵武市| 雅安市| 澎湖县| 永清县| 团风县| 金阳县| 贺州市| 淅川县| 新乡县| 延寿县| 柞水县| 横峰县| 玛多县| 朔州市| 常山县| 大城县| 高青县| 屯留县| 合江县| 香格里拉县| 韶关市| 卓资县| 芜湖市| 昭通市| 根河市| 垦利县| 潮安县| 陆良县| 华池县|