Hello
How can I trigger an alert after checking the results for 3 minuets
So for example, if I want that the alert will trigger if count>1 , I would like to check for 3 minutes if count>1 and only then raise the alert
How can i do it ?
Hi @sarit_s ,
you have to schedule your alert every three minutes and insert a stats count and a threshold, so if you want to count the events where there's an error, you could schedule every three minutes an alert like this:
index=your_index error="your_error"
| stats count
| where count>1then you have to configure your alert to trigger if results are greater than zero.
Ciao.
Giuseppe