I want to repeat same alert 3 times, 5 minutes apart like morning call.
please let me know How can I do it.
Can I organize the logic into queries? or is there any alert option for it?
this is my query for alert event.
index="main" sourcetype="orcl_sourcetype" | sort by _time | tail 1 | where CNT < 10
Hi
You should just define that it's using cron schedule and there add schedule as
*/3 * * * *
That will run it every 3rd minutes.
Then don' t add throttling for it.
More info from
r. Ismo
Hi
You should just define that it's using cron schedule and there add schedule as
*/3 * * * *
That will run it every 3rd minutes.
Then don' t add throttling for it.
More info from
r. Ismo
It works! I really thanks for the response!