I have enabled few alerts and these are the criterias:
Alert Type: Scheduled by CRON
Time Range: 24 Hours
Cron Expression: * */4 * * *
So as per this expression: The search query will run every 4 hour for the last 24 hours and trigger alerts. (Mail in my case)
Last day my search event count was 350. So why it didnt trigger after it crossed the 120 mark?
Can any one help me on this?
Current Search Query:
(index=mesb "Statusc=ERROR") source="*/mule-app-csoneloggingv2.0-v201712091010.log" Attribute_1c=CMROLEUNAVAILABLE | eval time=strptime(CreatedDate, "%Y-%m-%dT%H:%M:%S.%3N%Z") | timechart span=1h count by Attribute1__c
Should I change to :
(index=mesb "Statusc=ERROR") source="*/mule-app-csoneloggingv2.0-v201712091010.log" Attribute_1c=CMROLEUNAVAILABLE | timechart span=1h count by Attribute1_c??
Can you put the search query in
101010 sample code format? Also, are you setting any threshold on the number of results? I see from your question that
120 is the threshold.
My advice is to set the threshold in a query itself and just create an alert as it is without setting any threshold on the UI.