Creating Alerts

Security Requirements and Controls

Alerts are constructed using queries and associated with one or more actions that will be triggered when the query runs. When typing a query to create an alert, the type of alert is automatically selected for you. This will adjust which configuration operations are available. They are summarized in the table below.

Configuration Aggregate Alert Filter Alert Legacy Alert
General Parameters Configurable in the General section of the Alert Properties. Creating an Alert, General section Creating an Alert, General section
Query Yes, using aggregates except bucket(), timeChart() start(), end(), now(), and Join Query Functions Yes, aggregates and joins are not supported Yes, using aggregates except bucket() and Join Query Functions
Actions Yes, see Actions Yes, see Actions Yes, see Actions
Throttling Yes, seeSetting Alert Throttle Period Yes, seeSetting Alert Throttle Period Yes, seeSetting Alert Throttle Period
Action Retries Yes, for a single action; when multiple actions are configured, no retry is performed if at least one action is successfully invoked. Yes, for a single action; when multiple actions are configured, no retry is performed if at least one action is successfully invoked. Yes, for a single action; when multiple actions are configured, no retry is performed if at least one action is successfully invoked.

Creating an Alert from the Alerts Overview

  1. Go to the Automation tab on the top bar of the User Interface and select Alerts from the menu on the left, the full list of available alerts appears in the Alerts overview page:

    Alerts Overview

    Figure 189. Alerts Overview


    The table lists the currently configured alerts for the selected repository or view, with information such as the alert name, type, the status of the action attached to the alert, etc. Use this page for filtering and managing alerts.

  2. Click + New alert on the top right and the Search page is displayed in Creating new alert mode — it is streamlined to only include the relevant Time Selector and Run buttons.

    Simplified Search page

    Figure 190. Simplified Search page


  3. Type a query for your alert and click Run

  4. Fill in the Details side panel on the right, as depicted in Figure 192, “New Alert Details”.

  5. Click the Save button on top: the new alert is now displayed in the alerts' overview, see Figure 189, “Alerts Overview”.