Hi Team,
With the below search query I have set the email Alert configuration, To only me as a testing which was working good.
index=index_name "Disk Alert 1 sent, Disk utilization at or near capacity"
My Quires are
1) I have mentioned, the complete line from the log file is "Disk Alert 1 sent, Disk utilization at or near capacity Partition=log, Usage=98%", So I want the email to trigger if the value is greater then 80% ? How and where this filter need to applied?
2) Alert which I created, I getting emails alerts and can able to open. Same I forward My teammate but he not able to open that, I verified Sharing category is private. In fact while I am creating the Alert I don’t see any option to select as private or public. By default it was Private.
So how can I modify that ?
3) In the same alert, I have mentioned my team DL email address instead if my ID when i try the run it is not triggering any email.
Could you please me to set email alert to the team to access/view ?
Please do let me know if my query is not clear & need any more detail information. You can email me at fine.
-Paul
1) Since "Usage" is already a field with a value, you should be able to set up your alert by specifying that it should be above 80. Before that, you'll need to get rid of the "%" though
index=index_name "Disk Alert 1 sent, Disk utilization at or near capacity" | rex mode=sed field=Usage "s/%//g" | where Usage>80
2) To let your colleague look at the alert, be sure to set the alert to "Shared in App" when creating it.
3) Not sure what you mean by that, but if the problem is that your team cannot view the alert, the solution to 2) should work for this too.
1) Since "Usage" is already a field with a value, you should be able to set up your alert by specifying that it should be above 80. Before that, you'll need to get rid of the "%" though
index=index_name "Disk Alert 1 sent, Disk utilization at or near capacity" | rex mode=sed field=Usage "s/%//g" | where Usage>80
2) To let your colleague look at the alert, be sure to set the alert to "Shared in App" when creating it.
3) Not sure what you mean by that, but if the problem is that your team cannot view the alert, the solution to 2) should work for this too.
Thank you very much for the answer