basic conditional alert

noun

A scheduled alert or rolling-window alert that is triggered when set thresholds in the number of events, sources, or hosts in its results are exceeded. For example, you could set up a basic conditional alert that is triggered when the number of events returned by the scheduled run of a search is greater than 10.

You can also design advanced conditional alerts, where the alert is based on a secondary search that evaluates the results of the search with which the alert is associated.

For more information

In the Alerting Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time