Rolling-window alert

noun

A real-time alert that monitors events within a rolling time window of a width that you define. The alert is triggered when its conditions are met by events as they pass through this window.

You can throttle per-result alerts to ensure that they aren't triggered too frequently. You can arrange to have the alert be triggered once for all the results that meet the alerting condition, or triggered once for each result that meets the alerting condition.

When you create an alert you can designate it as a per-result alert by selecting Monitor in real-time over a rolling window of... on the Schedule step of the Create Alert dialog.

Related terms

For more information

In the User Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time