Hi,
I am trying to create an alert that triggers when more than 5 files are deleted in less than 3 minutes from the app we monitor.
For some reason, the alert only works for single file deletion but does not work when I set it for. a number of events. any idea why? would love to get some help
attached a screen shot, in the actions it send an email to out ticking system
thats the query I used: host="ip-of the host" "event_type..tag"=file_delete
works for single file deletion