Legacy Alerts

Similar to Aggregate Alerts, Legacy alerts work by returning the results from an aggregate query; when the query returns an aggregate result with one or more rows, the alert is triggered. Legacy alerts have the following attributes and behavior:

The following limitations for Legacy alerts are known:

  • If an error occurs, Legacy alerts keep running so when they eventually succeed it will be for a different search interval and possibly a different result.

  • When throttling, the next search after the Legacy alerts trigger does not start exactly when the throttle period ends, which means that events right before or after might be missed.

For improved reliability, these limitations have been addressed in the aggregate alert type. For more information, see Aggregate Alerts.