advanced conditional alert

noun

Applicable to both scheduled alerts or rolling-window alerts, an advanced conditional alert is is based on the outcome of a conditional search that has been evaluated against the original results of the alert's base search (either a scheduled search or a real-time search evaluating events in a rolling time window).

If the outcome of the conditional search meets specific conditions, then the alert is triggered. For example, one could set up an advanced conditional alert that is triggered when the conditional search against the result data from the alert's base search returns more than 100 events.

You can also design basic conditional alerts, where alert actions are triggered when the results of the base search pass a specific threshold.

For more information

In the User Manual:

In the Admin Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time