scheduled alert

noun

An alert based on a historical, scheduled search, that is triggered when specific conditions are met by the results of a scheduled run of said search. Best for cases where immediate reaction to an alert is not a priority.

You can throttle scheduled alerts to ensure that they are not triggered too frequently. You can arrange to have the alert be triggered once for all the results that meet the alerting condition, or triggered once for each result that meets the alerting condition.

When you create an alert you can designate it as a scheduled alert by selecting Run on a schedule once every... on the Schedule step of the Create Alert dialog.

Related terms

For more information

In the User Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time